Offline verification of local evidence carriers, fleet briefs, and hash-only trade-safety receipts.
Four tools with complete JSON schemas, clear descriptions (100-200 chars), and proper parameter typing. All tools are READ_ONLY with explicit risk annotations. Naming follows verb_noun pattern (verify_*, project_*). Schemas include minLength constraints and enums. However, descriptions lack actionable recovery guidance for error cases, and no output schemas are documented. Tool composition is sound, each does one thing, but error handling patterns are absent.
Verify one local carrier and project it to a bounded transport format. Restricted, unsafe, or expired payloads remain blocked or redacted by policy.
Verify one local carrier JSON file under the configured root. Returns identity and rights-aware export disposition, never market advice.
Verify one local, content-addressed fleet brief under the configured root. Replays the exact recorded evaluation clock without fetching or mutating data.
Verify one local order-bound receipt under the configured root at an explicit clock. This v1 tool accepts no authentication secrets, so HMAC receipts fail closed and require tenant-local verification. It never fetches market data, recommends, or executes an order.
No output schemas documented. LLMs cannot infer what fields to expect from verify_carrier, project_carrier, verify_fleet_brief, or verify_trade_safety_receipt responses. This blocks downstream tool chaining and forces agents to guess at response structure.
Error handling descriptions missing. Tools state 'never market advice' and 'fail closed' but do not explain what error responses look like or how agents should recover. No guidance on retryability, user-fixable vs fatal errors, or actionable error messages.
evaluated_at parameter descriptions lack format guidance. While RFC 3339 UTC is mentioned, descriptions do not state 'must end in Z' or provide an example format. LLMs may pass malformed timestamps.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 62 | 2026-07-28+ | v2 |
project_carrier format enum lacks descriptions for each option (arrow, cloudevent, csl, fdc3, flat, jsonld, openlineage, otel). LLMs cannot determine which format to select without understanding what each produces.
STDIO transport only. Server is not remotely accessible and cannot be used by hosted MCP clients. Limits deployment to local/containerized environments.