mcp-proofDelivery report

memory

✓ SHIP-READY — all MUST checks pass, no blocking security findings, no behavioural drift
Server under test
npx -y @modelcontextprotocol/server-memory
Generated
2026-08-24 18:16 UTC · mcp-proof v0.7.2
Protocol
negotiated 2025-11-25 · initialize-handshake era · newest initialize-handshake revision
Behaviour fingerprint
sha256:25be77913dae047a3f926ad44f0f012deb393ac54cfb872789e9e2869fe3647f
Conformance
16/16
MUST checks passed · 7/7 SHOULD
Security
1
finding · 0 blocking · 1 advisory
Behaviour regression
4/4
replays clean · gate PASS
Evidence scope. This report proves what was observed on the wire: protocol conformance of the served surface, static analysis of advertised tool metadata, and behavioural equality against the recorded fixture baseline. It does not assess deployment, source code, process controls or authorization/OAuth flows — MSSS controls that need such evidence are marked manual review (or partial), never assumed.

Protocol conformance

CheckLevelResultDetails
LIFE-01 MUST ✓ PASS
initialize returns protocolVersion, capabilities and serverInfo
protocolVersion, capabilities and serverInfo all present
LIFE-02 SHOULD ✓ PASS
server negotiates the newest handshake revision (2025-11-25)
negotiated 2025-11-25, the newest revision the initialize handshake carries
LIFE-03 MUST ✓ PASS
server answers tools/list after the initialized notification
tools/list returned 9 tool(s) across 1 page(s) after initialized
LIST-01 MUST ✓ PASS
tools/list pagination terminates (no cursor loop)
single page, no pagination cursor
RPC-01 MUST ✓ PASS
unknown method gets a JSON-RPC error response
unknown method rejected with error code -32601
RPC-02 SHOULD ✓ PASS
unknown method error code is -32601 (method not found)
expected -32601, got -32601
RPC-03 MUST ✓ PASS
malformed tools/call params are rejected with an error
malformed params rejected with error code -32603
TOOL-01 MUST ✓ PASS
every tool has a non-empty name and an inputSchema
all 9 tools have a name and an inputSchema
TOOL-02 SHOULD ✓ PASS
every tool has a non-empty description
all 9 tools carry a description
TOOL-03 MUST ✓ PASS
every tool inputSchema compiles as JSON Schema
all 9 inputSchemas compile as JSON Schema draft 2020-12
TOOL-04 MUST ✓ PASS
calling a nonexistent tool is rejected
rejected as tool result with isError=true
TOOL-05 MUST ✓ PASS
a call missing required arguments is rejected
create_entities with empty args rejected via isError=true
TOOL-06 MUST ✓ PASS
declared outputSchemas compile as JSON Schema
all 9 declared outputSchema(s) compile
TOOL-08 MUST ✓ PASS
observed structuredContent matches the declared outputSchema
read_graph structuredContent validates against its outputSchema
TOOL-07 SHOULD ✓ PASS
declared input constraints are enforced
4 schema-violating input(s) across 3 tool(s), all rejected
RES-01 MUST ✓ PASS
advertised resources capability serves resources/list
resources/list returned 1 resource(s)
RES-02 MUST ✓ PASS
every resource carries a uri and a name
all 1 resource(s) carry a uri and a name
RES-03 MUST ✓ PASS
resources/read returns contents for an advertised resource
read memory://knowledge-graph: 1 content entr(y/ies), uri echoed
RES-04 MUST ✓ PASS
resources/list pagination terminates (no cursor loop)
single page, no pagination cursor
PROMPT-01 MUST – SKIP
advertised prompts capability serves prompts/list
prompts capability not advertised
PROMPT-02 MUST – SKIP
every prompt has a name and well-formed argument metadata
prompts/list unavailable
PROMPT-03 MUST – SKIP
prompts/get rejects a call missing required arguments
no prompt declares required arguments
PROMPT-04 MUST – SKIP
prompts/list pagination terminates (no cursor loop)
no surface to paginate
CAP-02 SHOULD ✓ PASS
declared capabilities match served features (resources)
capabilities.resources declared and resources/list served
CAP-03 SHOULD ✓ PASS
declared capabilities match served features (prompts)
capabilities.prompts not declared and prompts/list not served
HYG-01 MUST ✓ PASS
stdout carries only JSON-RPC messages
no non-JSON-RPC stdout lines observed
CAP-01 SHOULD ✓ PASS
declared capabilities match served features (tools)
capabilities.tools declared and tools/list served

Security & hygiene

CheckDomainResultDetails
SEC-01 MCP-INPUT-01 ✓ PASS
no prompt-injection patterns in tool descriptions
0 matches across 9 tools
SEC-02 MCP-INPUT-01 ✓ PASS
no invisible or bidi control characters in tool metadata
0 invisible characters across 9 tools
SEC-03 MCP-LOG-02 ✓ PASS
no secret-looking strings in tool metadata
0 secret-like strings across 9 tools
SEC-04 MCP-INPUT-02 ! WARN
injection-surface string params carry constraints
unconstrained injection-surface params: search_nodes.query
Fix: Add enum, pattern or maxLength to path/url/command-like string params.
SEC-05 MCP-INPUT-01 ✓ PASS
tool descriptions stay under 2000 chars
longest description 106 chars across 9 tools
SEC-06 MCP-EXEC-01,MCP-EXEC-02 ✓ PASS
no tool advertises unconstrained arbitrary execution
0 exec-style tools with free-form params across 9 tools

MSSS compliance

L1: 1/2 auto-assessable controls met · 1 partial · 4 require manual review. Mapped against MSSS v0.1 (control-level mapping v2.0 (2026-01-20)): 3 of 24 controls are auto-assessable from this audit's deterministic checks (partial = evidence ran clean but cannot prove the control on its own); the remaining 21 need deployment, code or process evidence and are marked manual review — never assessed by this tool.

Behaviour regression

FixtureToolVerdictDetail
0001__add_observations__8643bb3c.json add_observations OK
0002__read_graph__44136fa3.json read_graph OK
0003__search_nodes__38e762cf.json search_nodes OK
0004__open_nodes__179d490f.json open_nodes OK

Leave-behind: your regression gate

The recorded fixtures (demo/fixtures-memory, suite fingerprint sha256:0f403be6a740a840b5aeb8787f6d378500856183a7965a318d98be4ab2d0b1f5) are the behavioural contract of this server. Keep them in the repository and run the workflow below in CI — any breaking or value drift fails the build before it reaches your users.

# The recorded fixtures in demo/fixtures-memory are the behavioral contract: any drift fails this job.
name: mcp-proof regression gate
on:
  push:
  pull_request:
jobs:
  replay:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: "3.11"
      - name: Install mcp-proof
        run: pip install git+https://github.com/YuCPbit/mcp-proof
      - name: Replay golden fixtures against the live server
        run: mcp-proof replay --fixtures demo/fixtures-memory -- npx -y @modelcontextprotocol/server-memory

Recommended next steps

  1. P1SEC-04 — Add enum, pattern or maxLength to path/url/command-like string params.