{
  "id": "CG-FIXTURE-MCP-TOOL-INTEGRITY-0.1.0",
  "version": "0.1.0",
  "authorization": "Publisher-created inert fixtures using a disclosed synthetic key, no customer data, and no external MCP server.",
  "inventoryFormat": "CapitalGuard-normalized inventory derived for gate testing; not a raw MCP tools/list response.",
  "sourceVectorUrl": "https://capitalguard.io/mcp-integrity/v0.1.0/test-vectors.json",
  "syntheticKeyNotice": "The vector signature uses a fixed synthetic test key. It is not a production credential or independent certification.",
  "claimBoundary": "CapitalGuard pins an approved MCP server identity and exact tool inventory, validates calls against the pinned input schema, requires an already-verified one-time gateway approval for mutating or unknown tools, and keeps untrusted result content out of agent context unless the registry permits closed structured data. Direct MCP calls, dishonest identity measurement, approved-tool vulnerabilities, host compromise, and content released outside this gate remain outside its authority.",
  "inventory": {
    "schemaVersion": "cg-mcp-inventory-0.1.0",
    "server": {
      "id": "mcp.synthetic-release",
      "identityDigestSha256": "1111111111111111111111111111111111111111111111111111111111111111",
      "protocolVersion": "2025-06-18"
    },
    "tools": [
      {
        "description": "Return a fixed closed status object.",
        "inputSchema": {
          "additionalProperties": false,
          "properties": {
            "scope": {
              "enum": [
                "repository",
                "workspace"
              ],
              "type": "string"
            }
          },
          "required": [
            "scope"
          ],
          "type": "object"
        },
        "name": "read_status",
        "outputSchema": {
          "additionalProperties": false,
          "properties": {
            "count": {
              "maximum": 1000,
              "minimum": 0,
              "type": "integer"
            },
            "status": {
              "enum": [
                "clear",
                "review"
              ],
              "type": "string"
            }
          },
          "required": [
            "count",
            "status"
          ],
          "type": "object"
        },
        "title": "Read status"
      },
      {
        "description": "Return external text for local quarantine.",
        "inputSchema": {
          "additionalProperties": false,
          "properties": {
            "recordId": {
              "maxLength": 64,
              "minLength": 1,
              "type": "string"
            }
          },
          "required": [
            "recordId"
          ],
          "type": "object"
        },
        "name": "fetch_external_record",
        "outputSchema": null,
        "title": "Fetch external record"
      },
      {
        "description": "Perform a synthetic mutating operation.",
        "inputSchema": {
          "additionalProperties": false,
          "properties": {
            "environment": {
              "enum": [
                "staging"
              ],
              "type": "string"
            }
          },
          "required": [
            "environment"
          ],
          "type": "object"
        },
        "name": "deploy_release",
        "outputSchema": null,
        "title": "Deploy release"
      }
    ]
  },
  "inventoryDigestSha256": "35ac0db4edcea08f058edb4288ce2eaf489cb84d63469155994f5453581bba94",
  "policies": [
    {
      "effect": "read_only",
      "maxResponseBytes": 2048,
      "resultMode": "strict_data",
      "serverId": "mcp.synthetic-release",
      "tool": "read_status"
    },
    {
      "effect": "read_only",
      "maxResponseBytes": 4096,
      "resultMode": "quarantine",
      "serverId": "mcp.synthetic-release",
      "tool": "fetch_external_record"
    },
    {
      "effect": "mutating",
      "maxResponseBytes": 2048,
      "resultMode": "metadata_only",
      "serverId": "mcp.synthetic-release",
      "tool": "deploy_release"
    }
  ],
  "registry": {
    "claimBoundary": "CapitalGuard pins an approved MCP server identity and exact tool inventory, validates calls against the pinned input schema, requires an already-verified one-time gateway approval for mutating or unknown tools, and keeps untrusted result content out of agent context unless the registry permits closed structured data. Direct MCP calls, dishonest identity measurement, approved-tool vulnerabilities, host compromise, and content released outside this gate remain outside its authority.",
    "issuedAt": "2026-07-18T12:00:00.000Z",
    "registryId": "CGMCPREG-SYNTHETIC-RELEASE-01",
    "schemaVersion": "cg-mcp-registry-0.1.0",
    "servers": [
      {
        "identityDigestSha256": "1111111111111111111111111111111111111111111111111111111111111111",
        "inventoryDigestSha256": "35ac0db4edcea08f058edb4288ce2eaf489cb84d63469155994f5453581bba94",
        "protocolVersion": "2025-06-18",
        "serverId": "mcp.synthetic-release",
        "tools": [
          {
            "definitionDigestSha256": "bcdcdadd26cc3da0507eb7e13fd0c15c887435bcfe362fdac892dd8da2a12e9d",
            "effect": "mutating",
            "inputSchemaDigestSha256": "8e0002c044088ac8e4b16301208c0f234f504532cdf5cf977b34ac5ac169f622",
            "maxResponseBytes": 2048,
            "name": "deploy_release",
            "outputSchemaDigestSha256": null,
            "resultMode": "metadata_only"
          },
          {
            "definitionDigestSha256": "f821c0fcc689baff0bfb4217a0f227a0cf3cb6f1952d06f1f6f7514ee28a534f",
            "effect": "read_only",
            "inputSchemaDigestSha256": "273e0423460a8ed6859fed9385d41c5b3c5675e0d86ba1a1df2702bdb96be658",
            "maxResponseBytes": 4096,
            "name": "fetch_external_record",
            "outputSchemaDigestSha256": null,
            "resultMode": "quarantine"
          },
          {
            "definitionDigestSha256": "521d57d53753e0f608c3bd82397fda7ad3da6cfa7a0c50fc31dac14a9a50d298",
            "effect": "read_only",
            "inputSchemaDigestSha256": "d32e6d3be3a22e452d757b9078f4907599a96a5bf01064671aa40abc6684a43a",
            "maxResponseBytes": 2048,
            "name": "read_status",
            "outputSchemaDigestSha256": "2e6d2dd70d71696141f12c69ce278eacbe33a26636788c14dbe2322d48085df6",
            "resultMode": "strict_data"
          }
        ]
      }
    ],
    "version": "0.1.0",
    "signature": {
      "algorithm": "hmac-sha256",
      "value": "b7fb09b14844e28734def92493cd1f3d138f83fc529599c2db61dae694208367"
    }
  },
  "scenarios": [
    {
      "expected": "verified",
      "id": "CGMCP-TV-001",
      "mutation": "none"
    },
    {
      "expected": "blocked_before_invoke",
      "id": "CGMCP-TV-002",
      "mutation": "server identity digest changed"
    },
    {
      "expected": "blocked_before_invoke",
      "id": "CGMCP-TV-003",
      "mutation": "tool description changed"
    },
    {
      "expected": "blocked_before_invoke",
      "id": "CGMCP-TV-004",
      "mutation": "input schema gained a property"
    },
    {
      "expected": "blocked_before_invoke",
      "id": "CGMCP-TV-005",
      "mutation": "mutating call lacks require_approval decision"
    },
    {
      "expected": "quarantined",
      "id": "CGMCP-TV-006",
      "mutation": "provider returns arbitrary text"
    },
    {
      "expected": "blocked",
      "id": "CGMCP-TV-007",
      "mutation": "same request reserved twice concurrently"
    },
    {
      "expected": "blocked_after_invoke",
      "id": "CGMCP-TV-008",
      "mutation": "result exceeds signed byte limit"
    }
  ]
}
