MCP integrity benchmark 0.1
Catch MCP tool drift before invocation.
In a publisher-run test, the CapitalGuard gate matched all eight declared outcomes in a fixed synthetic MCP harness.
Identity, description, schema, and missing-approval changes stopped before the provider ran. Untrusted text was quarantined, a duplicate call was blocked, and oversized output was refused.
CapitalGuard Security Research · Version 0.1.0 · Tested July 28, 2026
Case-level evidence
Eight declared boundaries. Eight exact matches.
| Case | Check | Expected | Observed | Provider calls | Result |
|---|---|---|---|---|---|
| CGMCP-TV-001 | Intact signed tool inventory | verified | verified | 1 | Match |
| CGMCP-TV-002 | Server identity drift | blocked before invoke | blocked before invoke | 0 | Match |
| CGMCP-TV-003 | Tool description drift | blocked before invoke | blocked before invoke | 0 | Match |
| CGMCP-TV-004 | Input schema expansion | blocked before invoke | blocked before invoke | 0 | Match |
| CGMCP-TV-005 | Mutating call without approval | blocked before invoke | blocked before invoke | 0 | Match |
| CGMCP-TV-006 | Untrusted provider text | quarantined | quarantined | 1 | Match |
| CGMCP-TV-007 | Concurrent request replay | blocked | blocked | 1 | Match |
| CGMCP-TV-008 | Oversized provider result | blocked after invoke | blocked after invoke | 1 | Match |
Publisher-run release
Inspect the fixtures. Verify result consistency.
The release publishes a CapitalGuard-normalized inert inventory, eight case declarations, case-level output, methodology, standalone fixture/results verifier, and SHA-256 manifest. Its registry uses a fixed, disclosed synthetic key to test deterministic consistency; it is not publisher identity, independent attestation, or certification.
Run digest: 95576e30cbea053ec8abc158bb651e666e9bca3af84bceee8f3b0d5f1a3f14a7
What this evidence does not prove
This publisher-operated synthetic benchmark records only the declared CapitalGuard MCP Integrity Gate 0.1 outcomes on one fixed CapitalGuard-normalized inventory and provider harness. It does not execute or assess a vendor product, model, live MCP server, customer environment, exploit, or network action; estimate attack success, false-negative, or false-positive rates; certify an implementation; independently attest the publisher-run execution; or guarantee protection.
The inventory, calls, provider output, key, and repository roots are deterministic synthetic fixtures.
The benchmark covers eight declared cases, not every MCP implementation, schema, transport, authentication mode, or tool behavior.
The gate depends on trustworthy server-identity measurement, protected signing material, and invocation routing through the enforcing adapter.
An approved tool can still contain a vulnerability or harmful business logic that inventory integrity alone cannot detect.
Quarantined content requires a separate human-controlled review path; releasing it outside the gate is beyond this result.
Primary sources checked July 28, 2026
Apply the boundary
