receipt · MCPAudit report: sample_audit_report

reading room · 394 words · 2 min

MCPAudit report: sample_audit_report

Trust receipt for MCPAudit report: sample_audit_report: MCPAudit report summarized with policy and risk limitations. Includes checks, evidence, exclusions, freshness, and limitations.

Trust Receipt

trust receipt issues found

MCPAudit reported capability, drift, risk, and policy signals for configured MCP servers.

Verdict

failed MCPAudit report summarized with policy and risk limitations.

Freshness

static_fixture 2026-05-09T09:00:00Z

Checks

6 2 passed, 3 failed, 0 not checked, 1 inconclusive

Receipt ID

tr_mcpaudit-sample-audit-report 2026-06-27T00:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Failed

  • High-risk server count failed

  • 1 high-risk server(s) reported.

  • mcpaudit-json-report

  • Schema drift findings failed

  • 1 drift finding(s) reported.

  • mcpaudit-json-report

  • Policy gate failed

  • Policy result failed with 1 violation(s).

    • max_risk (high): Server risk score 8.0 meets or exceeds policy limit 7.0.
  • mcpaudit-json-report

Inconclusive

  • Tool annotation coverage inconclusive

  • Minimum annotation coverage was 0%; some risk may rely on scanner inference or MCP spec defaults.

  • mcpaudit-json-report

Passed

  • MCPAudit scan completed passed

  • Report covers 1 discovered server(s).

    • servers_connected=1

    • total_tools=1

    • permission_findings=1

    • capability_findings=1

    • injection_findings=0

    • drift_findings=1

    • top_composite_risk=8.0

  • mcpaudit-json-report

  • Connection failures passed

  • 0 server(s) failed to connect.

  • mcpaudit-json-report

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

ID Title Kind Reference Digest
mcpaudit-json-report MCPAudit JSON report json local-public-safe-input:mcpaudit-json-report 118c7a720361f424...

Intentionally Excluded

Credential values and raw private configReceipts summarize report metadata and counts, not raw credential-bearing MCP client configs.

Server launch details and local pathsThe adapter intentionally omits command arguments, config paths, resource URIs, and env key names from generated receipt text.

Raw tool schemas and prompt/resource textThe receipt records counts and normalized checks only. Inspect the source report for full scanner detail.

Limitations

MCPAudit risk is a capability and finding summary, not a claim that a server is malicious.

This receipt does not connect to MCP servers, verify package provenance, or download package artifacts itself.

Policy-gate meaning depends on the policy file used when the source report was generated.

Summary-only receipts may omit individual tool names, local paths, resource URIs, and credential key names for public safety.

Reproduce Or Inspect

Generate an MCPAudit report.mcp-audit scan --json report.json

Generate this receipt.trust-receipt mcpaudit --input report.json

Payload SHA-256: 99d78559522bccd892fd307fd775a18943aec98390d19719c739c741a54472e3

Generated by trust-receipt-generator 0.1.0

payload sha-256 · 99d78559522bccd892fd307fd775a18943aec98390d19719c739c741a54472e3