mcp-proof / effect evidence
| Check | Level | Result | Details |
|---|---|---|---|
| EFF-01 | MUST | ✓ PASS | readOnlyHint is honoured (no observed external write) 10 readOnly-annotated tool call(s) caused no observed external write |
| EFF-02 | MUST | ✓ PASS | observed deletes are consistent with destructiveHint (explicit false contradicted ⇒ fail; unset ⇒ spec default true) all 1 observed deleted object(s) consistent with declared/default destructive semantics: 1 call(s) from tools declaring destructiveHint=true |
| EFF-03 | SHOULD | ✓ PASS | idempotentHint is honoured (a repeated identical call is a no-op) 2 repeated idempotent call(s) left external state unchanged |
| EFF-06 | SHOULD | – SKIP | created authority does not outlive its authorizing grant no created authority-bearing object to assess |
Declared annotations beside the effect an independent observer saw, the response a response-only auditor would have read, the objects that resulted, and the probe's authority / dependency verdict.
| Call | Declared | Observed effect | Response seen | Objects / persistence | Authority (probed) | Lineage |
|---|---|---|---|---|---|---|
create_directory {"path": "<jail>/workspace"} | readOnlyHint=False, destructiveHint=False, idempotentHint=True, openWorldHint=False | create observed observed 1 change(s): create fs/workspace | Successfully created directory <jail>/workspace | create fs/workspace persistent | unknown unknown probe inconclusive | by: — needs: — |
create_directory {"path": "<jail>/workspace"} | readOnlyHint=False, destructiveHint=False, idempotentHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | Successfully created directory <jail>/workspace | — — | not authority observed no object created | by: — needs: — |
write_file {"path": "<jail>/workspace/a.txt", "content": "alpha v1\n"} | readOnlyHint=False, destructiveHint=True, idempotentHint=True, openWorldHint=False | create observed observed 1 change(s): create fs/workspace/a.txt | Successfully wrote to <jail>/workspace/a.txt | create fs/workspace/a.txt ephemeral | unknown unknown probe inconclusive | by: — needs: — |
write_file {"path": "<jail>/workspace/a.txt", "content": "alpha v1\n"} | readOnlyHint=False, destructiveHint=True, idempotentHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | Successfully wrote to <jail>/workspace/a.txt | — — | not authority observed no object created | by: — needs: — |
read_file {"path": "<jail>/workspace/a.txt"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | alpha v1 | — — | not authority observed no object created | by: — needs: — |
read_text_file {"path": "<jail>/workspace/a.txt"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | alpha v1 | — — | not authority observed no object created | by: — needs: — |
read_media_file {"path": "<jail>/workspace/a.txt"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | — | — — | not authority observed no object created | by: — needs: — |
read_multiple_files {"paths": ["<jail>/workspace/a.txt"]} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | <jail>/workspace/a.txt: alpha v1 | — — | not authority observed no object created | by: — needs: — |
get_file_info {"path": "<jail>/workspace/a.txt"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | size: 9 created: Tue Sep 22 2026 14:07:40 GMT+0800 (China… | — — | not authority observed no object created | by: — needs: — |
list_directory {"path": "<jail>"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | [DIR] workspace | — — | not authority observed no object created | by: — needs: — |
list_directory_with_sizes {"path": "<jail>"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | [DIR] workspace Total: 0 files, 1 … | — — | not authority observed no object created | by: — needs: — |
directory_tree {"path": "<jail>"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | [ { "name": "workspace", "type": "directory", … | — — | not authority observed no object created | by: — needs: — |
search_files {"path": "<jail>", "pattern": "a.txt"} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | No matches found | — — | not authority observed no object created | by: — needs: — |
list_allowed_directories {} | readOnlyHint=True, openWorldHint=False | none observed no external object changed between before/after snapshots | Allowed directories: <jail> <jail> | — — | not authority observed no object created | by: — needs: — |
edit_file {"path": "<jail>/workspace/a.txt", "edits": [{"oldText": "alpha v1", "newText": "alpha v2"}]} | readOnlyHint=False, destructiveHint=True, idempotentHint=False, openWorldHint=False | update observed observed 1 change(s): update fs/workspace/a.txt | ```diff Index: <jail>/workspace/a.txt ===================… | update fs/workspace/a.txt — | not authority observed call created no object to bear authority | by: — needs: — |
move_file {"source": "<jail>/workspace/a.txt", "destination": "<jail>/workspace/b.txt"} | readOnlyHint=False, destructiveHint=True, idempotentHint=False, openWorldHint=False | create observed observed 2 change(s): create fs/workspace/b.txt, delete fs/workspace/a.txt | Successfully moved <jail>/workspace/a.txt to <jail>/works… | create fs/workspace/b.txt, delete fs/workspace/a.txt persistent | unknown unknown probe inconclusive | by: — needs: — |