{"schemaVersion":"maha-epistemic/1.0","evidencePolicyVersion":"mps/0.1","generatedAt":"2026-08-24T00:00:00.000Z","domain":{"slug":"agentic-systems-mcp","name":"Agentic systems and MCP","description":"Tool protocols, capability boundaries, sandboxing, context degradation, coordination, deadlock, memory, injection, and evaluation traces.","stressPoint":"A successful tool call or benchmark trajectory does not establish least authority, resistance to prompt injection, reliable coordination, or safe autonomous operation.","accent":"green"},"lifecycle":{"status":"adversarial-pilot","foundationalTarget":30,"canonicalFactoryRecords":9,"outstandingFactoryRecords":21},"counts":{"graphRecords":30,"graphEdges":34,"publicCanonicalRecords":9,"withheldRecords":21},"records":[{"id":"urn:maha:record:agentic-systems-mcp-mcp-tool-result-contracts","title":"MCP tool result contracts","recordKind":"comparison","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/comparisons/agentic-systems-mcp-mcp-tool-result-contracts","contentHash":"sha256:eefbbb278989ba0fd59a8478fbf442b96363f6a60a54796c044d22f1cb6fe266","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-tool-result-contracts","scope":"Limited to Tool discovery, input schemas, calls, results, error handling, and security considerations. in “Model Context Protocol specification: Tools”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP tool result contracts does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"empirical-claim","sourceIds":["source-agentic-systems-mcp-mcp-tools"],"statement":"The cited source supports treating mcp tool result contracts as a distinct comparison within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-tools","url":"https://modelcontextprotocol.io/specification/draft/server/tools","title":"Model Context Protocol specification: Tools","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"Protocol conformance does not establish that a tool is safe, correctly authorized, idempotent, or resistant to malicious inputs.","publisher":"Model Context Protocol","establishes":"The specification defines protocol roles and message contracts for discovering and invoking server-exposed tools.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/draft/server/tools","scheme":"url"}],"publishedAt":"","exactLocator":"Tool discovery, input schemas, calls, results, error handling, and security considerations.","sourceChronology":{"status":"living-document","accessedAt":"2026-08-25","sourceVersion":"accessed-2026-08-25"}}],"boundaries":["MCP tool result contracts does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp tool result contracts record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-tool-deny-by-default","title":"Human denial control for tool invocations","recordKind":"concept","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/concepts/agentic-systems-mcp-human-denial-control-for-tool-invocations","contentHash":"sha256:fb08cfa074d0a89224e0050ea660ef99110e42e5faf48ee9fc425bbc598e6444","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-tool-deny-by-default","scope":"Limited to the User Interaction Model warning and the Security Considerations list on the Tools page of the Model Context Protocol specification, version 2024-11-05. It records what the specification recommends to implementors and does not describe any organisation’s allowlist, identity, retention, or approval policy.","boundary":"A recommendation addressed to implementors is not a protocol requirement, is not evidence that any deployed system denies tools by default, and establishes no system-level performance, safety, scalability, economic advantage, or deployment readiness.","claimKind":"empirical-claim","sourceIds":["source-agentic-systems-mcp-mcp-core"],"statement":"The Model Context Protocol specification recommends, as a normative SHOULD for implementors rather than a protocol mandate, that a human remain in the loop with the ability to deny tool invocations, and states that the protocol itself does not mandate any specific user interaction model.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-core","url":"https://modelcontextprotocol.io/specification/2024-11-05/server/tools","title":"Model Context Protocol specification","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"The specification recommends implementor behaviour and mandates server-side input validation and access control. It does not prescribe an organisation’s allowlist, identity, retention, or approval policy, and it expressly does not mandate a user interaction model.","publisher":"Model Context Protocol","establishes":"The Tools page states that for trust, safety and security there SHOULD always be a human in the loop with the ability to deny tool invocations, that the protocol itself does not mandate any specific user interaction model, that servers MUST implement proper access controls and validate tool inputs, and that clients SHOULD prompt for user confirmation on sensitive operations.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/2024-11-05/index","scheme":"url"}],"publishedAt":"2024-11-05","exactLocator":"Tools page, version 2024-11-05: the \"User Interaction Model\" warning block and the \"Security Considerations\" list."}],"boundaries":["A recommended human denial control does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded concept record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this human denial control record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract.","Do not read a recommended human ability to deny an invocation as a requirement that tools be denied unless explicitly permitted."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-client-server-roles","title":"MCP client server roles","recordKind":"concept","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/concepts/agentic-systems-mcp-mcp-client-server-roles","contentHash":"sha256:a6888640790d8a599276a2eac31a7c06149f3db71abc45cd5f9cd86fc78ecae8","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-client-server-roles","scope":"Limited to Tool discovery, input schemas, calls, results, error handling, and security considerations. in “Model Context Protocol specification: Tools”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP client server roles does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-mcp-tools"],"statement":"The cited source supports treating mcp client server roles as a distinct concept within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-tools","url":"https://modelcontextprotocol.io/specification/draft/server/tools","title":"Model Context Protocol specification: Tools","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"Protocol conformance does not establish that a tool is safe, correctly authorized, idempotent, or resistant to malicious inputs.","publisher":"Model Context Protocol","establishes":"The specification defines protocol roles and message contracts for discovering and invoking server-exposed tools.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/draft/server/tools","scheme":"url"}],"publishedAt":"","exactLocator":"Tool discovery, input schemas, calls, results, error handling, and security considerations.","sourceChronology":{"status":"living-document","accessedAt":"2026-08-25","sourceVersion":"accessed-2026-08-25"}}],"boundaries":["MCP client server roles does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp client server roles record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-resource-discovery","title":"MCP resource discovery","recordKind":"concept","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/concepts/agentic-systems-mcp-mcp-resource-discovery","contentHash":"sha256:0cee761b8549e1ef9fac658cba8f33a1adf93beb73304491e64ca9a9131ba53e","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-resource-discovery","scope":"Limited to Architecture, lifecycle, capabilities, resources, prompts, and security sections. in “Model Context Protocol specification”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP resource discovery does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-mcp-core"],"statement":"The cited source supports treating mcp resource discovery as a distinct concept within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-core","url":"https://modelcontextprotocol.io/specification/2024-11-05/index","title":"Model Context Protocol specification","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"A protocol primitive does not prescribe an organization’s allowlist, identity, retention, or approval policy.","publisher":"Model Context Protocol","establishes":"The specification defines client, server, and host roles and capability-negotiated protocol primitives.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/2024-11-05/index","scheme":"url"}],"publishedAt":"2024-11-05","exactLocator":"Architecture, lifecycle, capabilities, resources, prompts, and security sections."}],"boundaries":["MCP resource discovery does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp resource discovery record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-tool-input-schemas","title":"MCP tool input schemas","recordKind":"measurement","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/measurements/agentic-systems-mcp-mcp-tool-input-schemas","contentHash":"sha256:c5a7d068bdfece0b447130410f5563138bba215b4830f8b792e87eeb1bcc429d","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-tool-input-schemas","scope":"Limited to Tool discovery, input schemas, calls, results, error handling, and security considerations. in “Model Context Protocol specification: Tools”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP tool input schemas does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"observation","sourceIds":["source-agentic-systems-mcp-mcp-tools"],"statement":"The cited source supports treating mcp tool input schemas as a distinct measurement within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-tools","url":"https://modelcontextprotocol.io/specification/draft/server/tools","title":"Model Context Protocol specification: Tools","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"Protocol conformance does not establish that a tool is safe, correctly authorized, idempotent, or resistant to malicious inputs.","publisher":"Model Context Protocol","establishes":"The specification defines protocol roles and message contracts for discovering and invoking server-exposed tools.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/draft/server/tools","scheme":"url"}],"publishedAt":"","exactLocator":"Tool discovery, input schemas, calls, results, error handling, and security considerations.","sourceChronology":{"status":"living-document","accessedAt":"2026-08-25","sourceVersion":"accessed-2026-08-25"}}],"boundaries":["MCP tool input schemas does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp tool input schemas record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-context-window-position-effects","title":"Context window position effects","recordKind":"mechanism","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/mechanisms/agentic-systems-mcp-context-window-position-effects","contentHash":"sha256:ae1e72566f66d8884a168f9511f03940d97ecc2449f28aa0995583d48e534a69","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-context-window-position-effects","scope":"Limited to Long-context experiments, position effects, retrieval and question-answering tasks, and limitations. in “Lost in the Middle: How Language Models Use Long Contexts”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"Context window position effects does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-lost-middle"],"statement":"The cited source supports treating context window position effects as a distinct mechanism within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-lost-middle","url":"https://doi.org/10.1162/tacl_a_00638","title":"Lost in the Middle: How Language Models Use Long Contexts","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Nelson F. Liu","Kevin Lin","John Hewitt","et al."],"boundary":"Benchmark position effects do not define a universal token limit or predict every model and workflow.","publisher":"Transactions of the Association for Computational Linguistics","establishes":"The study reports position-dependent performance on specified long-context tasks and models.","identifiers":[{"value":"10.1162/tacl_a_00638","scheme":"doi"}],"publishedAt":"2024-01-01","exactLocator":"Long-context experiments, position effects, retrieval and question-answering tasks, and limitations."}],"boundaries":["Context window position effects does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this context window position effects record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-capability-negotiation","title":"MCP capability negotiation","recordKind":"mechanism","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/mechanisms/agentic-systems-mcp-mcp-capability-negotiation","contentHash":"sha256:419836e8b840f03bb8acc9f0441ea1284295b2a9c2a9ecde25ac5db8f569ce92","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-capability-negotiation","scope":"Limited to Tool discovery, input schemas, calls, results, error handling, and security considerations. in “Model Context Protocol specification: Tools”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP capability negotiation does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-mcp-tools"],"statement":"The cited source supports treating mcp capability negotiation as a distinct mechanism within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-tools","url":"https://modelcontextprotocol.io/specification/draft/server/tools","title":"Model Context Protocol specification: Tools","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"Protocol conformance does not establish that a tool is safe, correctly authorized, idempotent, or resistant to malicious inputs.","publisher":"Model Context Protocol","establishes":"The specification defines protocol roles and message contracts for discovering and invoking server-exposed tools.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/draft/server/tools","scheme":"url"}],"publishedAt":"","exactLocator":"Tool discovery, input schemas, calls, results, error handling, and security considerations.","sourceChronology":{"status":"living-document","accessedAt":"2026-08-25","sourceVersion":"accessed-2026-08-25"}}],"boundaries":["MCP capability negotiation does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp capability negotiation record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-prompt-templates","title":"MCP prompt templates","recordKind":"mechanism","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/mechanisms/agentic-systems-mcp-mcp-prompt-templates","contentHash":"sha256:2f6ebb7b7e376bcae1106aa4a135c6cc2dd94b6d5b8371e36c4a1702e3218549","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-prompt-templates","scope":"Limited to Architecture, lifecycle, capabilities, resources, prompts, and security sections. in “Model Context Protocol specification”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP prompt templates does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-mcp-core"],"statement":"The cited source supports treating mcp prompt templates as a distinct mechanism within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-core","url":"https://modelcontextprotocol.io/specification/2024-11-05/index","title":"Model Context Protocol specification","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"A protocol primitive does not prescribe an organization’s allowlist, identity, retention, or approval policy.","publisher":"Model Context Protocol","establishes":"The specification defines client, server, and host roles and capability-negotiated protocol primitives.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/2024-11-05/index","scheme":"url"}],"publishedAt":"2024-11-05","exactLocator":"Architecture, lifecycle, capabilities, resources, prompts, and security sections."}],"boundaries":["MCP prompt templates does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp prompt templates record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]},{"id":"urn:maha:record:agentic-systems-mcp-mcp-tool-discovery","title":"MCP tool discovery","recordKind":"method","reviewState":"published-canonical","canonicalPath":"/knowledge/agentic-systems-mcp/methods/agentic-systems-mcp-mcp-tool-discovery","contentHash":"sha256:752c9749b3936e0a7a28568f2e41430e3fef8546f0e52959a933848998b857ec","claims":[{"id":"urn:maha:claim:agentic-systems-mcp-mcp-tool-discovery","scope":"Limited to Tool discovery, input schemas, calls, results, error handling, and security considerations. in “Model Context Protocol specification: Tools”; this candidate records the concept boundary and does not pool results from uncited systems or studies.","boundary":"MCP tool discovery does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","claimKind":"theoretical-model","sourceIds":["source-agentic-systems-mcp-mcp-tools"],"statement":"The cited source supports treating mcp tool discovery as a distinct method within the stated agentic systems and mcp scope.","replication":{"asOfDate":"2026-08-24","assessment":"Independent replication and cross-platform transfer have not been compiled for this candidate; the evidence maturity refers only to the bounded source contract.","independentReplicationCount":null},"uncertainty":{"kind":"qualitative","statement":"No cross-source quantitative interval is asserted. Definitions, operating conditions, samples, instruments, and outcome measures must be checked against the exact cited locator during review."},"evidenceMaturity":"single-study"}],"sources":[{"id":"source-agentic-systems-mcp-mcp-tools","url":"https://modelcontextprotocol.io/specification/draft/server/tools","title":"Model Context Protocol specification: Tools","rights":{"note":"The candidate uses original boundary language and a short paraphrase linked to the cited source. No source passage, figure, or table is reproduced.","basis":"citation-with-paraphrase","quotationUsed":false},"authors":["Model Context Protocol contributors"],"boundary":"Protocol conformance does not establish that a tool is safe, correctly authorized, idempotent, or resistant to malicious inputs.","publisher":"Model Context Protocol","establishes":"The specification defines protocol roles and message contracts for discovering and invoking server-exposed tools.","identifiers":[{"value":"https://modelcontextprotocol.io/specification/draft/server/tools","scheme":"url"}],"publishedAt":"","exactLocator":"Tool discovery, input schemas, calls, results, error handling, and security considerations.","sourceChronology":{"status":"living-document","accessedAt":"2026-08-25","sourceVersion":"accessed-2026-08-25"}}],"boundaries":["MCP tool discovery does not by itself establish system-level performance, safety, manufacturability, scalability, economic advantage, clinical benefit, or deployment readiness.","A source-bounded mechanism, method, or measurement record does not establish manufacturing yield, economic advantage, safety, clinical benefit, or commercial readiness unless those outcomes are measured in a separately scoped record."],"prohibitedInferences":["Do not use this mcp tool discovery record to claim that the surrounding technology is proven, safe, scalable, commercially available, or strategically superior.","Do not transfer a reported result across hardware, organisms, protocols, datasets, operating conditions, or outcome definitions without a declared comparison contract."]}],"withheldInventory":{"recordCount":21,"edgeCount":25,"recordKinds":{"comparison":4,"concept":4,"measurement":5,"mechanism":3,"method":5},"disclosure":"aggregate-only"},"boundary":"Only active canonical records are enumerated. Draft identifiers, titles, paths, claims, sources, and gate reasons remain private until canonical release."}