Repository verification: MCPAudit
Trust receipt for Repository verification: MCPAudit: Repository verification summarized 6 passing check(s) against truth schema 0.7.0 with visible gaps. Includes checks, evidence, exclusions, freshness, and limitations.
Trust Receipt
trust receipt checks passed with limitations
This limitation-forward receipt summarizes bounded repository checks. It is not a certification, and it can say I don't know when evidence is missing.
Verdict
passed Repository verification summarized 6 passing check(s) against truth schema 0.7.0 with visible gaps.
Freshness
fresh 2026-07-08T01:37:44Z
Checks
7 6 passed, 0 failed, 1 not checked, 0 inconclusive
Receipt ID
tr_verify_mcpaudit 2026-07-08T01:37:55Z
Boundary
This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.
Not Checked
Liveness not checked
not_applicable: liveness only applies to web-deploy stack
- outcome=not_applicable
portfolio-verification-checkrun
Passed
Tests Present passed
pass: truth data reports a test suite
outcome=pass
derived_has_tests=True
portfolio-verification-checkrun
Tests Pass passed
pass: test command exited 0
outcome=pass
cmd=uv run pytest -q
duration_s=4.34
failed=0
passed=783
total=783
portfolio-verification-checkrun
Ci Present passed
pass: truth data reports CI workflows
outcome=pass
derived_has_ci=True
portfolio-verification-checkrun
Ci Green passed
pass: latest default-branch workflow succeeded
outcome=pass
conclusion=success
run_url=https://github.com/saagpatel/MCPAudit/actions/runs/28850482083
portfolio-verification-checkrun
License Present passed
pass: truth data reports a license file
outcome=pass
derived_has_license=True
portfolio-verification-checkrun
Claims Match passed
pass: one or more bounded claims were corroborated
outcome=pass
ledger_count=1
portfolio-verification-checkrun
Evidence
Evidence entries are public-safe references and digests, not raw private reports.
| ID | Title | Kind | Reference | Digest |
|---|---|---|---|---|
| portfolio-verification-checkrun | Portfolio repository verification check-run | json | local-public-safe-input:portfolio-verification-checkrun | d57db82a763e2dd3... |
Intentionally Excluded
Local filesystem paths and raw logsThe receipt includes bounded outcomes, counts, and short reasons only.
Secrets and private configurationThe check-run contract excludes credentials, token values, environment dumps, and private config.
Mutable repository stateThe runner is read-only for target repositories and does not record unbounded working-tree detail.
Limitations
A receipt is not a certification, approval, or live health guarantee.
External checks depend on local CLI availability, network access, and current provider state.
Claims matching is limited to mechanically checkable README signals in v1.
Passing checks do not prove security posture, maintainability, or release readiness.
Reproduce Or Inspect
Run a bounded portfolio verification check-run.python3 scripts/portfolio_verify_run.py --repo-id
Generate this receipt.trust-receipt repo-verify --input <check-run.json>
Payload SHA-256: 25328fa8cda8aa10b631524074e3cbdb6ccb1ddbcef341b34a59e03a0e6d1db6
Generated by trust-receipt-generator 0.1.0
payload sha-256 · 25328fa8cda8aa10b631524074e3cbdb6ccb1ddbcef341b34a59e03a0e6d1db6