mcp-proofDelivery report

everything

✓ SHIP-READY — all MUST checks pass, no blocking security findings
Server under test
npx -y @modelcontextprotocol/server-everything
Generated
2026-08-24 18:15 UTC · mcp-proof v0.7.2
Protocol
negotiated 2025-11-25 · initialize-handshake era · newest initialize-handshake revision
Behaviour fingerprint
sha256:010e06a86dfd57cb908ebcf8b76e0e471f50e750083950e3e0c6770af35d676d
Conformance
20/20
MUST checks passed · 7/7 SHOULD
Security
0
findings · 0 blocking · 0 advisory
Behaviour regression
not recorded (run mcp-proof record)
Evidence scope. This report proves what was observed on the wire: protocol conformance of the served surface, static analysis of advertised tool metadata. It does not assess deployment, source code, process controls or authorization/OAuth flows — MSSS controls that need such evidence are marked manual review (or partial), never assumed.

Protocol conformance

CheckLevelResultDetails
LIFE-01 MUST ✓ PASS
initialize returns protocolVersion, capabilities and serverInfo
protocolVersion, capabilities and serverInfo all present
LIFE-02 SHOULD ✓ PASS
server negotiates the newest handshake revision (2025-11-25)
negotiated 2025-11-25, the newest revision the initialize handshake carries
LIFE-03 MUST ✓ PASS
server answers tools/list after the initialized notification
tools/list returned 13 tool(s) across 1 page(s) after initialized
LIST-01 MUST ✓ PASS
tools/list pagination terminates (no cursor loop)
single page, no pagination cursor
RPC-01 MUST ✓ PASS
unknown method gets a JSON-RPC error response
unknown method rejected with error code -32601
RPC-02 SHOULD ✓ PASS
unknown method error code is -32601 (method not found)
expected -32601, got -32601
RPC-03 MUST ✓ PASS
malformed tools/call params are rejected with an error
malformed params rejected with error code -32603
TOOL-01 MUST ✓ PASS
every tool has a non-empty name and an inputSchema
all 13 tools have a name and an inputSchema
TOOL-02 SHOULD ✓ PASS
every tool has a non-empty description
all 13 tools carry a description
TOOL-03 MUST ✓ PASS
every tool inputSchema compiles as JSON Schema
all 13 inputSchemas compile as JSON Schema draft 2020-12
TOOL-04 MUST ✓ PASS
calling a nonexistent tool is rejected
rejected as tool result with isError=true
TOOL-05 MUST ✓ PASS
a call missing required arguments is rejected
echo with empty args rejected via isError=true
TOOL-06 MUST ✓ PASS
declared outputSchemas compile as JSON Schema
all 1 declared outputSchema(s) compile
TOOL-08 MUST ✓ PASS
observed structuredContent matches the declared outputSchema
get-structured-content structuredContent validates against its outputSchema
TOOL-07 SHOULD ✓ PASS
declared input constraints are enforced
4 schema-violating input(s) across 3 tool(s), all rejected
RES-01 MUST ✓ PASS
advertised resources capability serves resources/list
resources/list returned 7 resource(s)
RES-02 MUST ✓ PASS
every resource carries a uri and a name
all 7 resource(s) carry a uri and a name
RES-03 MUST ✓ PASS
resources/read returns contents for an advertised resource
read demo://resource/static/document/architecture.md: 1 content entr(y/ies), uri echoed
RES-04 MUST ✓ PASS
resources/list pagination terminates (no cursor loop)
single page, no pagination cursor
PROMPT-01 MUST ✓ PASS
advertised prompts capability serves prompts/list
prompts/list returned 4 prompt(s)
PROMPT-02 MUST ✓ PASS
every prompt has a name and well-formed argument metadata
all 4 prompt(s) carry valid metadata
PROMPT-03 MUST ✓ PASS
prompts/get rejects a call missing required arguments
args-prompt with empty args rejected (code -32602)
PROMPT-04 MUST ✓ PASS
prompts/list pagination terminates (no cursor loop)
single page, no pagination cursor
CAP-02 SHOULD ✓ PASS
declared capabilities match served features (resources)
capabilities.resources declared and resources/list served
CAP-03 SHOULD ✓ PASS
declared capabilities match served features (prompts)
capabilities.prompts declared and prompts/list served
HYG-01 MUST ✓ PASS
stdout carries only JSON-RPC messages
no non-JSON-RPC stdout lines observed
CAP-01 SHOULD ✓ PASS
declared capabilities match served features (tools)
capabilities.tools declared and tools/list served

Security & hygiene

CheckDomainResultDetails
SEC-01 MCP-INPUT-01 ✓ PASS
no prompt-injection patterns in tool descriptions
0 matches across 13 tools
SEC-02 MCP-INPUT-01 ✓ PASS
no invisible or bidi control characters in tool metadata
0 invisible characters across 13 tools
SEC-03 MCP-LOG-02 ✓ PASS
no secret-looking strings in tool metadata
0 secret-like strings across 13 tools
SEC-04 MCP-INPUT-02 ✓ PASS
injection-surface string params carry constraints
0 unconstrained injection-surface params across 13 tools
SEC-05 MCP-INPUT-01 ✓ PASS
tool descriptions stay under 2000 chars
longest description 270 chars across 13 tools
SEC-06 MCP-EXEC-01,MCP-EXEC-02 ✓ PASS
no tool advertises unconstrained arbitrary execution
0 exec-style tools with free-form params across 13 tools

MSSS compliance

L1: 1/2 auto-assessable controls met · 1 partial · 4 require manual review. Mapped against MSSS v0.1 (control-level mapping v2.0 (2026-01-20)): 3 of 24 controls are auto-assessable from this audit's deterministic checks (partial = evidence ran clean but cannot prove the control on its own); the remaining 21 need deployment, code or process evidence and are marked manual review — never assessed by this tool.

Recommended next steps

  1. KEEPCommit the fixtures directory and the CI workflow above — behavioural drift will then fail the build before users see it.
  2. KEEPRe-audit after the next MCP spec revision or any SDK upgrade; identical behaviour reproduces the same fingerprint, so before/after is provable.