mcp-proof / effect evidence

saas-testbed (honest)

1 advisory finding(s)
Observation boundary. Effects are read out-of-band via an out-of-band SQLite read of the server's state store, never from the tools' own responses. Authority and effectiveness come from a probe that exercises created objects: exercising each created credential against the server's real auth rule. Dimensions no channel can establish are marked unknown and their checks SKIP — never a silent pass. This is a controlled measurement instrument; findings here are about the audited server, not production prevalence.
Calls observed10
Authority objects3

Effect-conformance checks

CheckLevelResultDetails
EFF-01MUST✓ PASS
readOnlyHint is honoured (no observed external write)
3 readOnly-annotated tool call(s) caused no observed external write
EFF-02MUST✓ PASS
observed deletes are consistent with destructiveHint (explicit false contradicted ⇒ fail; unset ⇒ spec default true)
all 1 observed deleted object(s) consistent with declared/default destructive semantics: 1 call(s) from tools declaring destructiveHint=true
EFF-03SHOULD– SKIP
idempotentHint is honoured (a repeated identical call is a no-op)
no idempotentHint-annotated (non-readOnly) tool was called twice with identical arguments
EFF-06SHOULD! WARN
created authority does not outlive its authorizing grant
create_api_key→api_keys/key_0001 authorized_by grant_root but depends_on nothing revocable (object not currently effective; no live dependency to probe); create_webhook→webhooks/wh_0001 authorized_by grant_root but depends_on ['self:webhooks:wh_0001'] (survives revoking grant:grant_root; revoking self:webhooks:wh_0001 disables it); create_share_link→share_links/share_0001 authorized_by grant_root but depends_on ['self:share_links:share_0001'] (survives revoking grant:grant_root; revoking self:share_links:share_0001 disables it)
Fix: An object minted under a grant should stop working when that grant is revoked; a probe found it still effective, so revocation of the delegation will not disable it (residual authority).

Per-call effect ledger

Declared annotations beside the effect an independent observer saw, the response a response-only auditor would have read, the objects that resulted, and the probe's authority / dependency verdict.

CallDeclaredObserved effectResponse seen Objects / persistenceAuthority (probed)Lineage
save_note
{"title": "welcome", "body": "hello world"}
—create observed
observed 1 change(s): create notes/welcome
saved 'welcome'create notes/welcome
ephemeral
not authority probed
probe: notes rows carry no credential to exercise
by: grant_root
needs: —
ping
{}
readOnlyHint=Truenone observed
no external object changed between before/after snapshots
ok—
—
not authority observed
no object created
by: —
needs: —
list_notes
{}
readOnlyHint=Truenone observed
no external object changed between before/after snapshots
["welcome"]—
—
not authority observed
no object created
by: —
needs: —
get_note
{"title": "welcome"}
readOnlyHint=Truenone observed
no external object changed between before/after snapshots
hello world—
—
not authority observed
no object created
by: —
needs: —
create_api_key
{"label": "ci"}
—create observed
observed 1 change(s): create api_keys/key_0001
{"key_id": "key_0001", "secret": "sk_test_bd24723ab694a02…create api_keys/key_0001
persistent
authority-bearing probed
probe: exercised api_keys.secret: server auth rule accepts it (status/expiry checked)
by: grant_root
needs: nothing revocable (residual)
create_webhook
{"url": "https://example.com/hook"}
—create observed
observed 1 change(s): create webhooks/wh_0001
{"webhook_id": "wh_0001", "secret": "sk_test_fcbfb6a77963…create webhooks/wh_0001
persistent
authority-bearing probed
probe: exercised webhooks.secret: server auth rule accepts it (status/expiry checked)
by: grant_root
needs: self:webhooks:wh_0001
create_share_link
{"title": "welcome"}
—create observed
observed 1 change(s): create share_links/share_0001
{"share_id": "share_0001", "token": "sk_test_9268f02577b5…create share_links/share_0001
persistent
authority-bearing probed
probe: exercised share_links.token: server auth rule accepts it (status/expiry checked)
by: grant_root
needs: self:share_links:share_0001
revoke_api_key
{"key_id": "key_0001"}
destructiveHint=Trueupdate observed
observed 1 change(s): update api_keys/key_0001
revoked 1 key(s)update api_keys/key_0001
—
not authority observed
call created no object to bear authority
by: —
needs: —
cleanup_notes
{}
destructiveHint=Truenone observed
no external object changed between before/after snapshots
cleaned 0 temp note(s)—
—
not authority observed
no object created
by: —
needs: —
delete_note
{"title": "welcome"}
destructiveHint=Truedelete observed
observed 1 change(s): delete notes/welcome
deleted 1 note(s)delete notes/welcome
—
not authority observed
call created no object to bear authority
by: —
needs: —