Trust Receipt trust receiptpartial proof with gaps

MCP live readback: saagarpatel-portfolio

The deployed public MCP discovery manifest had a valid detached Ed25519 signature and its advertised read-only MCP endpoint responded to a point-in-time smoke check.

Verdict
mixed
MCP live readback summarized with signature, tool-contract, and uptime/key-custody limits.
Freshness
static_fixture
2026-06-28T01:48:14Z
Checks
8
7 passed, 0 failed, 1 not checked, 0 inconclusive
Receipt ID
tr_mcp-live-saagarpatel-portfolio
2026-06-28T02:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Not Checked

Uptime and key custody
not checked
The readback does not prove future uptime, DNS state, or private signing-key custody.
mcp-live-readback-summary

Passed

Public manifest readback
passed
Manifest advertised status=live and endpoint https://mcp.saagarpatel.dev/mcp.
  • manifest_url=https://saagarpatel.dev/.well-known/mcp.json
  • transport=streamable-http
  • authentication=none
mcp-live-readback-summary
Detached manifest signature
passed
Ed25519 signature validity was True.
  • signature_url=https://saagarpatel.dev/.well-known/mcp.json.sig
  • public_key_url=https://saagarpatel.dev/.well-known/mcp-ed25519.pub
mcp-live-readback-summary
Local and live manifest contract match
passed
Live manifest endpoint and tools matched the local public manifest contract.
mcp-live-readback-summary
Advertised tool contract
passed
6 live tool(s) matched the manifest tool list.
  • tools=get_document,get_operant_results,get_profile,list_corpus,list_projects,search
mcp-live-readback-summary
Read-only and closed-world annotations
passed
Live tools reported read-only and closed-world annotations during the smoke check.
mcp-live-readback-summary
OPERANT tool smoke result
passed
get_operant_results returned 9 model row(s).
mcp-live-readback-summary
Hosted PR checks
passed
Hosted verify=success, visual=success.
mcp-live-readback-summary

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

IDTitleKindReferenceDigest
mcp-live-readback-summaryMCP live-readback summaryjsonlocal-public-safe-input:mcp-live-readback-summary1ae82182d634d382...

Intentionally Excluded

Private signing key
Only the public key URL and signature status are included. Private key material is never part of a public receipt.
Raw MCP responses
The receipt records tool names, annotations, and aggregate smoke-check results, not full response payloads.
Local deployment paths and operator machine details
The adapter intentionally keeps local worktree paths, shell paths, runner paths, and private deploy state out of public artifacts.

Limitations

This receipt proves only a point-in-time public readback summary, not future uptime or future DNS state.
A valid detached signature proves the public manifest bytes matched the public key at readback time; it is not a key-custody audit.
Read-only tool annotations reduce advertised mutation risk but do not certify every future implementation behavior.
Hosted PR check success is build evidence, not a safety certification or approval to trust arbitrary MCP calls.

Reproduce Or Inspect

Run the live readback in the portfolio-index repo.
node scripts/check-mcp-live.mjs
Record only public-safe fields in a summary JSON fixture.
Keep private keys, raw responses, local paths, and deployment credentials excluded.
Generate this receipt.
trust-receipt mcp-live --input mcp-live-readback-summary.json