MCP Verify 1.0.630 trust-summary completeness
Date: 2026-08-14
Outcome
Trust-summary is now a compact, complete trust API. It no longer publishes a partial fallback whose values can happen to match the canonical detail page. A successful response always contains the request-current trust core and declares:
partial: false;fields_unavailable: [];materialization.state: complete;materialization.trust_core_complete: true;- no fallback
cache_note.
When the compact summary or canonical validation history cannot be loaded, the route returns a no-store 503 with Retry-After: 30. It does not substitute a historical or placeholder judgment.
Cache and timestamp contract
The internal trust-summary cache identity excludes the request query string. Tracking parameters and cache busters therefore reuse the canonical evidence entry rather than creating new fallback entries. The evidence snapshot ID continues to identify evidence lineage.
Every response re-evaluates the canonical trust core and refreshes generated_at, trust_evaluated_at, and materialization time. Successful and failure responses send browser, CDN, and surrogate no-store directives.
Report, policy, and compare retain their existing deep-detail fallback model. Their partial state is now structurally checkable: omitted fields are named, the cache note and materialization state agree, and the trust core remains complete. Compare exposes this contract at its top level as well as in its server snapshots.
Coherence monitoring
scripts/verify_trust_surface_coherence.py now validates materialization as a first-class invariant. The synthetic fails when detail or trust-summary is partial, cacheable, missing completeness metadata, carrying a fallback note, or exposing stale evaluation/generation times. It calls both the canonical trust-summary URL and a unique-query variant, then requires both to be complete and on the same evidence snapshot.
Partial report, policy, and compare responses are accepted only when their omissions, cache note, and materialization metadata agree and trust_core_complete is true. Stable trust values are still compared, but matching scores can no longer conceal a degraded response.
Instruction references and remediations
The instruction-reference probe now unions every deterministic extraction form. In addition to code-formatted names and constrained use/call/prefer phrases, it recognizes tool-like identifiers in explicit safety statements such as archive_passport is irreversible. Unconstrained snake-case prose is still ignored. Tracepass's current instruction sentence therefore identifies both archive_passport and suspend_passport.
Connector publishability, official-registry publication, and server-card schema omission remediations now have concrete actions and three-step playbooks. Schema omission uses a direct corrective title. The instruction finding has explicit family precedence: the primary check remediation wins, while the alert-derived response remains available when the primary row is absent or suppressed.
Compatibility
No scoring formula, compatibility threshold, database schema, or public schema version changes in this release. Remediation priority remains independent from active-alert severity.