Exposes MemGuard validation tools that AI agents can call natively via the Model Context Protocol (MCP). Tools allow agents to check memory trustworthiness before acting on stored facts.
MemGuard exposes 4 tools with complete schemas and descriptions. Naming follows verb_noun convention (validate_, get_, report_, get_). Descriptions are substantive (100-200 chars) and explain WHEN to use each tool. However, output schemas are undocumented, LLMs cannot predict response structure. Error handling is absent from visible code. Parameters lack validation constraints (e.g., min_trust_score 0.0-1.0 is stated but not enforced). No tool annotations (readOnlyHint, destructiveHint). The server is single-tenant hardcoded, limiting production readiness.
Get overall health metrics for the agent's memory store. Use this to assess how reliable the current memory state is.
Retrieve only memories above a trust score threshold. Use instead of raw memory retrieval when accuracy is critical.
Report a memory that the agent suspects is stale based on new information encountered during a task. This triggers priority validation.
Check if a specific memory is still accurate before acting on it. Returns trust score and validation status. Call this before making decisions based on stored facts that might be outdated.
Output schemas undocumented. LLMs cannot predict response structure (fields, types, pagination). Forces agents to guess what data is returned.
No error handling guidance in visible code. Agents cannot distinguish retryable errors from fatal ones. No recovery hints (e.g., 'memory_id not found, try search_memories first').
No tool annotations. Missing readOnlyHint (get_* tools), destructiveHint (report_stale_memory writes), idempotentHint. Agents cannot reason about side effects.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Hardcoded DEFAULT_TENANT_ID in server.py (line 16) breaks multi-tenant deployments. TODO comment acknowledges this but no auth context resolution implemented.
get_trusted_memories accepts 'query' (semantic search) but no fallback if semantic search fails. No guidance on what happens if embedding service is down.