Repository verification: mcp-trust
Trust receipt for Repository verification: mcp-trust: Repository verification summarized 6 passing check(s) against truth schema 0.7.0 with visible gaps. Includes checks, evidence, exclusions, freshness, and limitations.
Trust Receipt
trust receipt checks passed with limitations
This limitation-forward receipt summarizes bounded repository checks. It is not a certification, and it can say I don't know when evidence is missing.
Verdict
passed Repository verification summarized 6 passing check(s) against truth schema 0.7.0 with visible gaps.
Freshness
fresh 2026-07-08T01:37:30Z
Checks
7 6 passed, 0 failed, 1 not checked, 0 inconclusive
Receipt ID
tr_verify_mcp-trust 2026-07-08T01:37:35Z
Boundary
This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.
Not Checked
Liveness not checked
not_applicable: liveness only applies to web-deploy stack
- outcome=not_applicable
portfolio-verification-checkrun
Passed
Tests Present passed
pass: truth data reports a test suite
outcome=pass
derived_has_tests=True
portfolio-verification-checkrun
Tests Pass passed
pass: test command exited 0
outcome=pass
cmd=uv run pytest -q
duration_s=1.177
failed=0
passed=291
total=291
portfolio-verification-checkrun
Ci Present passed
pass: truth data reports CI workflows
outcome=pass
derived_has_ci=True
portfolio-verification-checkrun
Ci Green passed
pass: latest default-branch workflow succeeded
outcome=pass
conclusion=success
run_url=https://github.com/saagpatel/mcp-trust/actions/runs/28704274738
portfolio-verification-checkrun
License Present passed
pass: truth data reports a license file
outcome=pass
derived_has_license=True
portfolio-verification-checkrun
Claims Match passed
pass: one or more bounded claims were corroborated
outcome=pass
ledger_count=2
portfolio-verification-checkrun
Evidence
Evidence entries are public-safe references and digests, not raw private reports.
| ID | Title | Kind | Reference | Digest |
|---|---|---|---|---|
| portfolio-verification-checkrun | Portfolio repository verification check-run | json | local-public-safe-input:portfolio-verification-checkrun | 7e05b8c67058b0c4... |
Intentionally Excluded
Local filesystem paths and raw logsThe receipt includes bounded outcomes, counts, and short reasons only.
Secrets and private configurationThe check-run contract excludes credentials, token values, environment dumps, and private config.
Mutable repository stateThe runner is read-only for target repositories and does not record unbounded working-tree detail.
Limitations
A receipt is not a certification, approval, or live health guarantee.
External checks depend on local CLI availability, network access, and current provider state.
Claims matching is limited to mechanically checkable README signals in v1.
Passing checks do not prove security posture, maintainability, or release readiness.
Reproduce Or Inspect
Run a bounded portfolio verification check-run.python3 scripts/portfolio_verify_run.py --repo-id
Generate this receipt.trust-receipt repo-verify --input <check-run.json>
Payload SHA-256: abb67aaa35e2035e8ddaa56d46f900d0366ea7c651048db643ce2b53d8fafb8f
Generated by trust-receipt-generator 0.1.0
payload sha-256 · abb67aaa35e2035e8ddaa56d46f900d0366ea7c651048db643ce2b53d8fafb8f