Advisory-lease + witnessed-audit coordination for concurrent autonomous agents over shared mutable state, via MCP (alpha)
Limen defines 6 tools with clear, domain-specific names (limen_acquire, limen_write, limen_release, limen_read, limen_attribute, limen_list_active_leases). All tools have descriptions (50 - 150 chars, within baseline 34 - 392 range). Input schemas are present with typed parameters and descriptions. However, output schemas are not documented in the source code provided, critical for LLM planning. Parameter descriptions are adequate but lack format constraints (e.g., 'path_pattern' does not specify regex or length limits). Error handling is mentioned (errorReporting=true) but recovery guidance is not visible in tool definitions. No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite clear risk levels (WRITE vs READ_ONLY). Composition is strong: tools form a coherent lease-based coordination workflow.
Acquire an advisory lease on a region (path or directory prefix) with a specified intent (read, write, or propose). Returns a lease ID that must be passed to limen_write and limen_release.
Query the witnessed audit trail for a path. Returns all recorded writes to that path, most recent first, with the agent label attributed to each write.
List all currently active leases. Returns lease ID, path pattern, intent, agent label, and expiration time for each.
Read the current content of a path under an active read or write lease. Returns the witnessed, coordinated state.
Release an active lease. After release, the agent can no longer write under that lease. The lease is removed from the active set and the write audit trail is finalized.
Record a write to a target path under an active lease. The write is witnessed and attributed to the agent holding the lease. Must be called after limen_acquire and before limen_release.
Output schemas not documented. LLMs cannot plan downstream calls or extract required fields (e.g., lease_id from limen_acquire, audit trail structure from limen_attribute). Baseline: 100% of A+ tools document return types.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) despite clear risk levels. limen_write and limen_release are destructive; limen_read and limen_attribute are read-only. Annotations enable LLMs to reason about safety and retry logic.
Parameter descriptions lack format constraints. 'path_pattern' and 'path' do not specify regex, length limits, or allowed characters. 'signature' does not document Ed25519 format or encoding. Baseline: descriptions should state format, range, and constraints.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | F | 49 | <=2025-11-25 | v2 |
Error handling and recovery guidance not visible in tool definitions. No indication of retryable vs fatal errors, or what the LLM should do if a lease expires or a write fails. Baseline: error responses must guide next steps.
limen_list_active_leases has no input parameters but no pagination support documented. If many leases exist, response could be large. Baseline: tools returning lists should support limit/offset and return total count.