mcp-proofDelivery report

sequential-thinking

✓ SHIP-READY — all MUST checks pass, no blocking security findings, no behavioural drift
Server under test
npx -y @modelcontextprotocol/server-sequential-thinking
Generated
2026-08-24 18:18 UTC · mcp-proof v0.7.2
Protocol
negotiated 2025-11-25 · initialize-handshake era · newest initialize-handshake revision
Behaviour fingerprint
sha256:bc5f496e1ee7e72eb72f14e446ff3b38fb5e928d8fabf6e52b8fa84b9f5ba3d1
Conformance
11/11
MUST checks passed · 7/7 SHOULD
Security
1
finding · 0 blocking · 1 advisory
Behaviour regression
1/1
replays clean · gate PASS
Evidence scope. This report proves what was observed on the wire: protocol conformance of the served surface, static analysis of advertised tool metadata, and behavioural equality against the recorded fixture baseline. It does not assess deployment, source code, process controls or authorization/OAuth flows — MSSS controls that need such evidence are marked manual review (or partial), never assumed.

Protocol conformance

CheckLevelResultDetails
LIFE-01 MUST ✓ PASS
initialize returns protocolVersion, capabilities and serverInfo
protocolVersion, capabilities and serverInfo all present
LIFE-02 SHOULD ✓ PASS
server negotiates the newest handshake revision (2025-11-25)
negotiated 2025-11-25, the newest revision the initialize handshake carries
LIFE-03 MUST ✓ PASS
server answers tools/list after the initialized notification
tools/list returned 1 tool(s) across 1 page(s) after initialized
LIST-01 MUST ✓ PASS
tools/list pagination terminates (no cursor loop)
single page, no pagination cursor
RPC-01 MUST ✓ PASS
unknown method gets a JSON-RPC error response
unknown method rejected with error code -32601
RPC-02 SHOULD ✓ PASS
unknown method error code is -32601 (method not found)
expected -32601, got -32601
RPC-03 MUST ✓ PASS
malformed tools/call params are rejected with an error
malformed params rejected with error code -32603
TOOL-01 MUST ✓ PASS
every tool has a non-empty name and an inputSchema
all 1 tools have a name and an inputSchema
TOOL-02 SHOULD ✓ PASS
every tool has a non-empty description
all 1 tools carry a description
TOOL-03 MUST ✓ PASS
every tool inputSchema compiles as JSON Schema
all 1 inputSchemas compile as JSON Schema draft 2020-12
TOOL-04 MUST ✓ PASS
calling a nonexistent tool is rejected
rejected as tool result with isError=true
TOOL-05 MUST ✓ PASS
a call missing required arguments is rejected
sequentialthinking with empty args rejected via isError=true
TOOL-06 MUST ✓ PASS
declared outputSchemas compile as JSON Schema
all 1 declared outputSchema(s) compile
TOOL-08 MUST – SKIP
observed structuredContent matches the declared outputSchema
runtime behaviour unobserved — sequentialthinking: call yielded no normal result
TOOL-07 SHOULD ✓ PASS
declared input constraints are enforced
2 schema-violating input(s) across 1 tool(s), all rejected
RES-01 MUST – SKIP
advertised resources capability serves resources/list
resources capability not advertised
RES-02 MUST – SKIP
every resource carries a uri and a name
resources/list unavailable
RES-03 MUST – SKIP
resources/read returns contents for an advertised resource
no listed resource to read
RES-04 MUST – SKIP
resources/list pagination terminates (no cursor loop)
no surface to paginate
PROMPT-01 MUST – SKIP
advertised prompts capability serves prompts/list
prompts capability not advertised
PROMPT-02 MUST – SKIP
every prompt has a name and well-formed argument metadata
prompts/list unavailable
PROMPT-03 MUST – SKIP
prompts/get rejects a call missing required arguments
no prompt declares required arguments
PROMPT-04 MUST – SKIP
prompts/list pagination terminates (no cursor loop)
no surface to paginate
CAP-02 SHOULD ✓ PASS
declared capabilities match served features (resources)
capabilities.resources not declared and resources/list not served
CAP-03 SHOULD ✓ PASS
declared capabilities match served features (prompts)
capabilities.prompts not declared and prompts/list not served
HYG-01 MUST ✓ PASS
stdout carries only JSON-RPC messages
no non-JSON-RPC stdout lines observed
CAP-01 SHOULD ✓ PASS
declared capabilities match served features (tools)
capabilities.tools declared and tools/list served

Security & hygiene

CheckDomainResultDetails
SEC-01 MCP-INPUT-01 ✓ PASS
no prompt-injection patterns in tool descriptions
0 matches across 1 tools
SEC-02 MCP-INPUT-01 ✓ PASS
no invisible or bidi control characters in tool metadata
0 invisible characters across 1 tools
SEC-03 MCP-LOG-02 ✓ PASS
no secret-looking strings in tool metadata
0 secret-like strings across 1 tools
SEC-04 MCP-INPUT-02 ✓ PASS
injection-surface string params carry constraints
0 unconstrained injection-surface params across 1 tools
SEC-05 MCP-INPUT-01 ! WARN
tool descriptions stay under 2000 chars
descriptions over 2000 chars: sequentialthinking (2781 chars)
Fix: Shorten oversized descriptions; long metadata prose is a common poisoning carrier.
SEC-06 MCP-EXEC-01,MCP-EXEC-02 ✓ PASS
no tool advertises unconstrained arbitrary execution
0 exec-style tools with free-form params across 1 tools

MSSS compliance

L1: 0/2 auto-assessable controls met · 2 partial · 4 require manual review. Mapped against MSSS v0.1 (control-level mapping v2.0 (2026-01-20)): 3 of 24 controls are auto-assessable from this audit's deterministic checks (partial = evidence ran clean but cannot prove the control on its own); the remaining 21 need deployment, code or process evidence and are marked manual review — never assessed by this tool.

Behaviour regression

FixtureToolVerdictDetail
0001__sequentialthinking__db7c8252.json sequentialthinking OK

Leave-behind: your regression gate

The recorded fixtures (demo/fixtures-sequential-thinking, suite fingerprint sha256:f276c898b6a0ef6833f2e456c61cae0a24f926ecf151e88b97160d9dba332f02) are the behavioural contract of this server. Keep them in the repository and run the workflow below in CI — any breaking or value drift fails the build before it reaches your users.

# The recorded fixtures in demo/fixtures-sequential-thinking are the behavioral contract: any drift fails this job.
name: mcp-proof regression gate
on:
  push:
  pull_request:
jobs:
  replay:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: "3.11"
      - name: Install mcp-proof
        run: pip install git+https://github.com/YuCPbit/mcp-proof
      - name: Replay golden fixtures against the live server
        run: mcp-proof replay --fixtures demo/fixtures-sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking

Recommended next steps

  1. P1SEC-05 — Shorten oversized descriptions; long metadata prose is a common poisoning carrier.