MCP integrity benchmark 0.1

Catch MCP tool drift before invocation.

In a publisher-run test, the CapitalGuard gate matched all eight declared outcomes in a fixed synthetic MCP harness.

Identity, description, schema, and missing-approval changes stopped before the provider ran. Untrusted text was quarantined, a duplicate call was blocked, and oversized output was refused.

CapitalGuard Security Research · Version 0.1.0 · Tested July 28, 2026

Case-level evidence

Eight declared boundaries. Eight exact matches.

CaseCheckExpectedObservedProvider callsResult
CGMCP-TV-001Intact signed tool inventoryverifiedverified1 Match
CGMCP-TV-002Server identity driftblocked before invokeblocked before invoke0 Match
CGMCP-TV-003Tool description driftblocked before invokeblocked before invoke0 Match
CGMCP-TV-004Input schema expansionblocked before invokeblocked before invoke0 Match
CGMCP-TV-005Mutating call without approvalblocked before invokeblocked before invoke0 Match
CGMCP-TV-006Untrusted provider textquarantinedquarantined1 Match
CGMCP-TV-007Concurrent request replayblockedblocked1 Match
CGMCP-TV-008Oversized provider resultblocked after invokeblocked after invoke1 Match

Publisher-run release

Inspect the fixtures. Verify result consistency.

The release publishes a CapitalGuard-normalized inert inventory, eight case declarations, case-level output, methodology, standalone fixture/results verifier, and SHA-256 manifest. Its registry uses a fixed, disclosed synthetic key to test deterministic consistency; it is not publisher identity, independent attestation, or certification.

Run digest: 95576e30cbea053ec8abc158bb651e666e9bca3af84bceee8f3b0d5f1a3f14a7

What this evidence does not prove

This publisher-operated synthetic benchmark records only the declared CapitalGuard MCP Integrity Gate 0.1 outcomes on one fixed CapitalGuard-normalized inventory and provider harness. It does not execute or assess a vendor product, model, live MCP server, customer environment, exploit, or network action; estimate attack success, false-negative, or false-positive rates; certify an implementation; independently attest the publisher-run execution; or guarantee protection.

The inventory, calls, provider output, key, and repository roots are deterministic synthetic fixtures.

The benchmark covers eight declared cases, not every MCP implementation, schema, transport, authentication mode, or tool behavior.

The gate depends on trustworthy server-identity measurement, protected signing material, and invocation routing through the enforcing adapter.

An approved tool can still contain a vulnerability or harmful business logic that inventory integrity alone cannot detect.

Quarantined content requires a separate human-controlled review path; releasing it outside the gate is beyond this result.

Primary sources checked July 28, 2026

Apply the boundary

Review the tool. Then enforce the boundary.