{
  "title": "MCP Blog Evidence Manifest",
  "lastVerified": "2026-08-25",
  "licenseNote": "Source metadata compiled for MCP Blog. Linked works retain their original copyrights and licenses.",
  "count": 285,
  "records": [
    {
      "ID": "S001",
      "Date": "2010-03-26",
      "Source type": "STANDARD",
      "Organization": "JSON-RPC Working Group",
      "Title": "JSON-RPC 2.0 Specification",
      "URL": "https://www.jsonrpc.org/specification",
      "Version": "2.0",
      "Historical claim supported": "Defines requests, responses, notifications, errors, and batching used by MCP.",
      "Durability": "DURABLE",
      "Claim supported": "Defines requests, responses, notifications, errors, and batching used by MCP. Requests, responses, notifications, errors and transport independence. Request, response, notification, error and transport-agnostic RPC semantics Request, response, notification and error object semantics used by MCP.",
      "Research packages": "1,2,3,5",
      "Authority": "Primary standard"
    },
    {
      "ID": "S002",
      "Date": "2016-06-27",
      "Source type": "DOCUMENTATION",
      "Organization": "Microsoft",
      "Title": "Language Server Protocol Overview",
      "URL": "https://microsoft.github.io/language-server-protocol/overviews/lsp/overview/",
      "Version": "",
      "Historical claim supported": "Primary architectural background for editor-client/language-server reuse and JSON-RPC capability negotiation.",
      "Durability": "DURABLE",
      "Claim supported": "Primary architectural background for editor-client/language-server reuse and JSON-RPC capability negotiation.",
      "Research packages": "1"
    },
    {
      "ID": "S003",
      "Date": "2012-10",
      "Source type": "RFC",
      "Organization": "IETF",
      "Title": "RFC 6749: The OAuth 2.0 Authorization Framework",
      "URL": "https://www.rfc-editor.org/rfc/rfc6749",
      "Version": "",
      "Historical claim supported": "Background for delegated authorization terminology.",
      "Durability": "DURABLE",
      "Claim supported": "Background for delegated authorization terminology.",
      "Research packages": "1"
    },
    {
      "ID": "S004",
      "Date": "2015-09",
      "Source type": "RFC",
      "Organization": "IETF",
      "Title": "RFC 7636: Proof Key for Code Exchange by OAuth Public Clients",
      "URL": "https://www.rfc-editor.org/rfc/rfc7636",
      "Version": "RFC 7636",
      "Historical claim supported": "PKCE requirements used in MCP authorization.",
      "Durability": "DURABLE",
      "Claim supported": "PKCE requirements used in MCP authorization. PKCE security properties for public clients",
      "Research packages": "1,4",
      "Authority": "Formal standards source"
    },
    {
      "ID": "S005",
      "Date": "2020-09",
      "Source type": "RFC",
      "Organization": "IETF",
      "Title": "RFC 8707: Resource Indicators for OAuth 2.0",
      "URL": "https://www.rfc-editor.org/rfc/rfc8707",
      "Version": "RFC 8707",
      "Historical claim supported": "Resource Indicators added to MCP authorization hardening.",
      "Durability": "DURABLE",
      "Claim supported": "Resource Indicators added to MCP authorization hardening. Audience-bound resource parameter",
      "Research packages": "1,4",
      "Authority": "Formal standards source"
    },
    {
      "ID": "S006",
      "Date": "2025-04",
      "Source type": "RFC",
      "Organization": "IETF",
      "Title": "RFC 9728: OAuth 2.0 Protected Resource Metadata",
      "URL": "https://www.rfc-editor.org/rfc/rfc9728",
      "Version": "RFC 9728",
      "Historical claim supported": "Protected-resource metadata used by MCP resource servers.",
      "Durability": "DURABLE",
      "Claim supported": "Protected-resource metadata used by MCP resource servers. Protected-resource metadata used by MCP authorization",
      "Research packages": "1,4",
      "Authority": "Formal standards source"
    },
    {
      "ID": "S007",
      "Date": "LIVE",
      "Source type": "INTERNET-DRAFT",
      "Organization": "IETF OAuth WG",
      "Title": "OAuth 2.1 Internet-Draft",
      "URL": "https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/",
      "Version": "",
      "Historical claim supported": "Status and evolving basis of MCP authorization framework.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Status and evolving basis of MCP authorization framework.",
      "Research packages": "1"
    },
    {
      "ID": "S008",
      "Date": "2014-11-08",
      "Source type": "STANDARD",
      "Organization": "OpenID Foundation",
      "Title": "OpenID Connect Discovery 1.0",
      "URL": "https://openid.net/specs/openid-connect-discovery-1_0.html",
      "Version": "",
      "Historical claim supported": "Discovery mechanism supported in MCP 2025-11-25.",
      "Durability": "DURABLE",
      "Claim supported": "Discovery mechanism supported in MCP 2025-11-25.",
      "Research packages": "1"
    },
    {
      "ID": "S009",
      "Date": "2023-03-23",
      "Source type": "BLOG",
      "Organization": "OpenAI",
      "Title": "ChatGPT plugins",
      "URL": "https://openai.com/index/chatgpt-plugins/",
      "Version": "",
      "Historical claim supported": "Pre-MCP vendor plugin architecture using manifests, APIs, and OAuth.",
      "Durability": "DURABLE",
      "Claim supported": "Pre-MCP vendor plugin architecture using manifests, APIs, and OAuth. Earlier vendor-specific plugin model using manifests, OpenAPI and OAuth.",
      "Research packages": "1,2"
    },
    {
      "ID": "S010",
      "Date": "2023-06-13",
      "Source type": "BLOG",
      "Organization": "OpenAI",
      "Title": "Function calling and other API updates",
      "URL": "https://openai.com/index/function-calling-and-other-api-updates/",
      "Version": "",
      "Historical claim supported": "Pre-MCP model function-calling history.",
      "Durability": "DURABLE",
      "Claim supported": "Pre-MCP model function-calling history. Pre-MCP function-calling history and structured model action selection. Public OpenAI function-calling introduction, JSON arguments and early security warning",
      "Research packages": "1,2,3",
      "Authority": "Primary vendor"
    },
    {
      "ID": "S011",
      "Date": "LIVE",
      "Source type": "DOCUMENTATION",
      "Organization": "Anthropic",
      "Title": "Tool use with Claude",
      "URL": "https://docs.anthropic.com/en/docs/agents-and-tools/tool-use/overview",
      "Version": "",
      "Historical claim supported": "Distinguishes vendor tool-use APIs from MCP interoperability.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Distinguishes vendor tool-use APIs from MCP interoperability. Client versus server tools and structured tool_use behavior",
      "Research packages": "1,3",
      "Authority": "Primary vendor"
    },
    {
      "ID": "S012",
      "Date": "2024-09-24",
      "Source type": "GIT_REPOSITORY",
      "Organization": "Model Context Protocol",
      "Title": "Specification repository metadata",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol",
      "Version": "",
      "Historical claim supported": "Repository creation predates the public announcement.",
      "Durability": "DURABLE",
      "Claim supported": "Repository creation predates the public announcement.",
      "Research packages": "1"
    },
    {
      "ID": "S013",
      "Date": "2024-09-24",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Initial import of MCP specification repository",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/commit/d06853c5e8255a57a759817fde7816266023b1a4",
      "Version": "early draft",
      "Historical claim supported": "Earliest public commit; states LSP inspiration, host/client/server/session terminology, resources, prompts, tools, sampling, stdio and SSE.",
      "Durability": "DURABLE",
      "Claim supported": "Earliest public commit; states LSP inspiration, host/client/server/session terminology, resources, prompts, tools, sampling, stdio and SSE. Earliest public repository evidence and explicit LSP inspiration.",
      "Research packages": "1,2"
    },
    {
      "ID": "S014",
      "Date": "2024-09-24",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Initial TypeScript SDK import",
      "URL": "https://github.com/modelcontextprotocol/typescript-sdk/commit/02e421c1f17962643d26ec00a512610fd51a49c0",
      "Version": "",
      "Historical claim supported": "Earliest public TypeScript SDK evidence.",
      "Durability": "DURABLE",
      "Claim supported": "Earliest public TypeScript SDK evidence.",
      "Research packages": "1"
    },
    {
      "ID": "S015",
      "Date": "2024-09-24",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Initial Python SDK import",
      "URL": "https://github.com/modelcontextprotocol/python-sdk/commit/4cbf8154306aa5b96b2bb3fc83ac5984d217a0f5",
      "Version": "",
      "Historical claim supported": "Earliest public Python SDK evidence.",
      "Durability": "DURABLE",
      "Claim supported": "Earliest public Python SDK evidence.",
      "Research packages": "1"
    },
    {
      "ID": "S016",
      "Date": "2024-10-03",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Add required capabilities for resources",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/commit/bb2a11f7b917e16acde225f9643b53c2c1da2252",
      "Version": "early draft",
      "Historical claim supported": "Shows capability declarations still being refined before launch.",
      "Durability": "DURABLE",
      "Claim supported": "Shows capability declarations still being refined before launch.",
      "Research packages": "1"
    },
    {
      "ID": "S017",
      "Date": "2024-10-16",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Initial guide documentation merge",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/commit/135fa8218f8fe64471b0b66fff851a3293664d44",
      "Version": "early draft",
      "Historical claim supported": "Pre-launch documentation work.",
      "Durability": "DURABLE",
      "Claim supported": "Pre-launch documentation work.",
      "Research packages": "1"
    },
    {
      "ID": "S018",
      "Date": "2024-11-19",
      "Source type": "GIT_REPOSITORY",
      "Organization": "Model Context Protocol",
      "Title": "Reference servers repository",
      "URL": "https://github.com/modelcontextprotocol/servers",
      "Version": "",
      "Historical claim supported": "Repository creation and evolution of reference servers.",
      "Durability": "DURABLE",
      "Claim supported": "Repository creation and evolution of reference servers.",
      "Research packages": "1"
    },
    {
      "ID": "S019",
      "Date": "2024-11-19",
      "Source type": "GIT_COMMIT",
      "Organization": "Model Context Protocol",
      "Title": "Initial reference servers commit",
      "URL": "https://github.com/modelcontextprotocol/servers/commit/37415258b914330d10ed0ea948d67ac8a410a384",
      "Version": "",
      "Historical claim supported": "First public reference-server monorepo commit.",
      "Durability": "DURABLE",
      "Claim supported": "First public reference-server monorepo commit. Earliest verified public reference server set.",
      "Research packages": "1,2"
    },
    {
      "ID": "S020",
      "Date": "2024-11-19",
      "Source type": "GIT_TREE",
      "Organization": "Model Context Protocol",
      "Title": "Initial reference-server repository tree",
      "URL": "https://github.com/modelcontextprotocol/servers/tree/37415258b914330d10ed0ea948d67ac8a410a384",
      "Version": "",
      "Historical claim supported": "Confirms initial public directories including everything, Google Drive, Git, Postgres, and Puppeteer.",
      "Durability": "DURABLE",
      "Claim supported": "Confirms initial public directories including everything, Google Drive, Git, Postgres, and Puppeteer.",
      "Research packages": "1"
    },
    {
      "ID": "S021",
      "Date": "2024-11-25",
      "Source type": "BLOG",
      "Organization": "Anthropic",
      "Title": "Introducing the Model Context Protocol",
      "URL": "https://www.anthropic.com/news/model-context-protocol",
      "Version": "Launch",
      "Historical claim supported": "Public launch, creators, SDKs, Claude Desktop support, example integrations, and stated integration problem.",
      "Durability": "DURABLE",
      "Claim supported": "Public launch, creators, SDKs, Claude Desktop support, example integrations, and stated integration problem. Public announcement, integration-fragmentation rationale, SDKs, Claude Desktop and example servers. MCP public announcement, integration-fragmentation rationale, initial SDK and host context Public launch, initial local-first integration rationale, initial SDK and host context",
      "Research packages": "1,2,3,4",
      "Authority": "Primary vendor"
    },
    {
      "ID": "S022",
      "Date": "2024-11-25",
      "Source type": "BLOG",
      "Organization": "Zed Industries",
      "Title": "Zed and the Model Context Protocol",
      "URL": "https://zed.dev/blog/mcp",
      "Version": "",
      "Historical claim supported": "Launch-day non-Anthropic host integration and explicit LSP comparison.",
      "Durability": "DURABLE",
      "Claim supported": "Launch-day non-Anthropic host integration and explicit LSP comparison. Zed launch-day MCP integration and collaboration with Anthropic.",
      "Research packages": "1,5"
    },
    {
      "ID": "S023",
      "Date": "LIVE",
      "Source type": "README",
      "Organization": "Model Context Protocol",
      "Title": "Model Context Protocol repository README",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/README.md",
      "Version": "",
      "Historical claim supported": "Current creator credit to David Soria Parra and Justin Spahr-Summers.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current creator credit to David Soria Parra and Justin Spahr-Summers. Official creator credit for David Soria Parra and Justin Spahr-Summers.",
      "Research packages": "1,2"
    },
    {
      "ID": "S024",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "MCP specification 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05",
      "Version": "2024-11-05",
      "Historical claim supported": "Authoritative launch-era specification overview.",
      "Durability": "DURABLE",
      "Claim supported": "Authoritative launch-era specification overview. Launch-era stateful architecture, initialization, stdio, HTTP+SSE and original capabilities. Initial released protocol overview and date-based revision Launch-era architecture, lifecycle, capabilities and trust guidance",
      "Research packages": "1,2,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S025",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Architecture 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/architecture",
      "Version": "2024-11-05",
      "Historical claim supported": "Launch-era host/client/server architecture.",
      "Durability": "DURABLE",
      "Claim supported": "Launch-era host/client/server architecture. Launch-era host, client, server, JSON-RPC and stateful-session architecture",
      "Research packages": "1,3",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S026",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Lifecycle 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/basic/lifecycle",
      "Version": "2024-11-05",
      "Historical claim supported": "Initialize/initialized handshake, version and capability negotiation.",
      "Durability": "DURABLE",
      "Claim supported": "Initialize/initialized handshake, version and capability negotiation. Launch-era initialize/initialized lifecycle and capability negotiation.",
      "Research packages": "1,5"
    },
    {
      "ID": "S027",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Transports 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/basic/transports",
      "Version": "2024-11-05",
      "Historical claim supported": "stdio and HTTP+SSE semantics.",
      "Durability": "DURABLE",
      "Claim supported": "stdio and HTTP+SSE semantics. Original stdio and HTTP+SSE transport behavior Original stdio and HTTP+SSE transport semantics",
      "Research packages": "1,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S028",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tools 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/server/tools",
      "Version": "2024-11-05",
      "Historical claim supported": "Launch-era tool listing and invocation.",
      "Durability": "DURABLE",
      "Claim supported": "Launch-era tool listing and invocation. Launch-era tool definition and model-controlled interaction guidance Launch-era tool discovery, invocation and human-control guidance",
      "Research packages": "1,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S029",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Resources 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/server/resources",
      "Version": "2024-11-05",
      "Historical claim supported": "URI-addressed resources, templates, and subscriptions.",
      "Durability": "DURABLE",
      "Claim supported": "URI-addressed resources, templates, and subscriptions. Launch-era resource semantics Launch-era resources, subscriptions and data exposure semantics",
      "Research packages": "1,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S030",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Prompts 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/server/prompts",
      "Version": "2024-11-05",
      "Historical claim supported": "Server-exposed prompt templates and user-controlled workflows.",
      "Durability": "DURABLE",
      "Claim supported": "Server-exposed prompt templates and user-controlled workflows. Launch-era prompt-template semantics",
      "Research packages": "1,3",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S031",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Roots 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/client/roots",
      "Version": "2024-11-05",
      "Historical claim supported": "Client-declared filesystem/project boundaries.",
      "Durability": "DURABLE",
      "Claim supported": "Client-declared filesystem/project boundaries.",
      "Research packages": "1"
    },
    {
      "ID": "S032",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Sampling 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/client/sampling",
      "Version": "2024-11-05",
      "Historical claim supported": "Server requests model sampling through client/host.",
      "Durability": "DURABLE",
      "Claim supported": "Server requests model sampling through client/host. Launch-era server-to-client sampling and user-control expectations",
      "Research packages": "1,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S033",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Logging 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/server/utilities/logging",
      "Version": "2024-11-05",
      "Historical claim supported": "Protocol logging method and notifications.",
      "Durability": "DURABLE",
      "Claim supported": "Protocol logging method and notifications.",
      "Research packages": "1"
    },
    {
      "ID": "S034",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Completion 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/server/utilities/completion",
      "Version": "2024-11-05",
      "Historical claim supported": "Argument-completion utility present at launch.",
      "Durability": "DURABLE",
      "Claim supported": "Argument-completion utility present at launch.",
      "Research packages": "1"
    },
    {
      "ID": "S035",
      "Date": "2025-03-26",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "MCP specification 2025-03-26",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26",
      "Version": "2025-03-26",
      "Historical claim supported": "Authoritative March 2025 revision.",
      "Durability": "DURABLE",
      "Claim supported": "Authoritative March 2025 revision.",
      "Research packages": "1"
    },
    {
      "ID": "S036",
      "Date": "2025-03-26",
      "Source type": "CHANGELOG",
      "Organization": "Model Context Protocol",
      "Title": "Key changes 2025-03-26",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26/changelog",
      "Version": "2025-03-26",
      "Historical claim supported": "OAuth framework, Streamable HTTP, batching, tool annotations, audio, progress, completions capability.",
      "Durability": "DURABLE",
      "Claim supported": "OAuth framework, Streamable HTTP, batching, tool annotations, audio, progress, completions capability. OAuth-based authorization, Streamable HTTP, JSON-RPC batching, tool annotations, audio, progress text and completions capability entered the released specification. OAuth framework, Streamable HTTP, batching, annotations, audio and completions Initial authorization framework, Streamable HTTP, annotations and batching Streamable HTTP, OAuth framework, batching and tool annotations.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S037",
      "Date": "2025-03-26",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Authorization 2025-03-26",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26/basic/authorization",
      "Version": "2025-03-26",
      "Historical claim supported": "First protocol authorization framework.",
      "Durability": "DURABLE",
      "Claim supported": "First protocol authorization framework. Initial OAuth-oriented remote authorization framework First protocol authorization framework for HTTP deployments",
      "Research packages": "1,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S038",
      "Date": "2025-03-26",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Streamable HTTP 2025-03-26",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26/basic/transports",
      "Version": "2025-03-26",
      "Historical claim supported": "Original Streamable HTTP, stateful session, optional SSE, backwards compatibility.",
      "Durability": "DURABLE",
      "Claim supported": "Original Streamable HTTP, stateful session, optional SSE, backwards compatibility. Original Streamable HTTP semantics, including POST/GET, optional SSE, resumability and optional Mcp-Session-Id session management.",
      "Research packages": "1,2"
    },
    {
      "ID": "S039",
      "Date": "2025-03-26",
      "Source type": "PR",
      "Organization": "Model Context Protocol",
      "Title": "PR #206: Streamable HTTP transport",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/206",
      "Version": "2025-03-26",
      "Historical claim supported": "Design history for replacing HTTP+SSE.",
      "Durability": "DURABLE",
      "Claim supported": "Design history for replacing HTTP+SSE.",
      "Research packages": "1"
    },
    {
      "ID": "S040",
      "Date": "2025-03-26",
      "Source type": "PR",
      "Organization": "Model Context Protocol",
      "Title": "PR #133: Authorization specification",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/133",
      "Version": "2025-03-26",
      "Historical claim supported": "Authorization proposal and merge history.",
      "Durability": "DURABLE",
      "Claim supported": "Authorization proposal and merge history.",
      "Research packages": "1"
    },
    {
      "ID": "S041",
      "Date": "2025-03-26",
      "Source type": "PR",
      "Organization": "Model Context Protocol",
      "Title": "PR #185: Tool annotations",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/pull/185",
      "Version": "2025-03-26",
      "Historical claim supported": "Origin of read-only, destructive, idempotent, and open-world hints.",
      "Durability": "DURABLE",
      "Claim supported": "Origin of read-only, destructive, idempotent, and open-world hints.",
      "Research packages": "1"
    },
    {
      "ID": "S042",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "MCP specification 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18",
      "Version": "2025-06-18",
      "Historical claim supported": "Authoritative June 2025 revision.",
      "Durability": "DURABLE",
      "Claim supported": "Authoritative June 2025 revision.",
      "Research packages": "1"
    },
    {
      "ID": "S043",
      "Date": "2025-06-18",
      "Source type": "CHANGELOG",
      "Organization": "Model Context Protocol",
      "Title": "Key changes 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/changelog",
      "Version": "2025-06-18",
      "Historical claim supported": "Batching removal, structured output, resource-server classification, Resource Indicators, elicitation, resource links.",
      "Durability": "DURABLE",
      "Claim supported": "Batching removal, structured output, resource-server classification, Resource Indicators, elicitation, resource links. JSON-RPC batching was removed; structured tool output, resource links, elicitation and authorization hardening were added. Batching removal, structured output, elicitation and authorization hardening Resource-server classification, protected-resource metadata, Resource Indicators and structured output Removal of batching, structured tool output, elicitation and authorization hardening.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S044",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Authorization 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization",
      "Version": "2025-06-18",
      "Historical claim supported": "OAuth resource-server model, protected resource metadata, PKCE, Resource Indicators.",
      "Durability": "DURABLE",
      "Claim supported": "OAuth resource-server model, protected resource metadata, PKCE, Resource Indicators. Resource Indicators, token audience validation and resource-server model Audience restrictions, protected resource metadata and token validation",
      "Research packages": "1,3,4",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S045",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tools 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/server/tools",
      "Version": "2025-06-18",
      "Historical claim supported": "Structured tool output and output schema.",
      "Durability": "DURABLE",
      "Claim supported": "Structured tool output and output schema. Structured tool output and outputSchema semantics",
      "Research packages": "1,3",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S046",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Elicitation 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/client/elicitation",
      "Version": "2025-06-18",
      "Historical claim supported": "Server-initiated user information request capability.",
      "Durability": "DURABLE",
      "Claim supported": "Server-initiated user information request capability.",
      "Research packages": "1"
    },
    {
      "ID": "S047",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Security best practices 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/basic/security_best_practices",
      "Version": "2025-06-18",
      "Historical claim supported": "Token passthrough, confused deputy, least privilege, and proxy risks.",
      "Durability": "DURABLE",
      "Claim supported": "Token passthrough, confused deputy, least privilege, and proxy risks.",
      "Research packages": "1"
    },
    {
      "ID": "S048",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "MCP specification 2025-11-25",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25",
      "Version": "2025-11-25",
      "Historical claim supported": "Authoritative one-year revision.",
      "Durability": "DURABLE",
      "Claim supported": "Authoritative one-year revision.",
      "Research packages": "1"
    },
    {
      "ID": "S049",
      "Date": "2025-11-25",
      "Source type": "CHANGELOG",
      "Organization": "Model Context Protocol",
      "Title": "Key changes 2025-11-25",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/changelog",
      "Version": "2025-11-25",
      "Historical claim supported": "OIDC discovery, icons, incremental scopes, URL elicitation, sampling tools, client metadata documents, experimental tasks, governance.",
      "Durability": "DURABLE",
      "Claim supported": "OIDC discovery, icons, incremental scopes, URL elicitation, sampling tools, client metadata documents, experimental tasks, governance. OIDC discovery, icon metadata, incremental scope consent, richer elicitation, CIMD, tool use in sampling and experimental Tasks entered the released specification. One-year revision changes including experimental Tasks OIDC discovery, CIMD, incremental consent, URL elicitation and experimental Tasks OIDC discovery, CIMD, expanded elicitation, experimental Tasks and governance changes.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S050",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tasks 2025-11-25",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/basic/utilities/tasks",
      "Version": "2025-11-25",
      "Historical claim supported": "Experimental core Tasks semantics.",
      "Durability": "DURABLE",
      "Claim supported": "Experimental core Tasks semantics.",
      "Research packages": "1"
    },
    {
      "ID": "S051",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "URL-mode elicitation 2025-11-25",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/client/elicitation",
      "Version": "2025-11-25",
      "Historical claim supported": "Sensitive/out-of-band user interactions.",
      "Durability": "DURABLE",
      "Claim supported": "Sensitive/out-of-band user interactions.",
      "Research packages": "1"
    },
    {
      "ID": "S052",
      "Date": "2025-09-26",
      "Source type": "BLOG",
      "Organization": "Model Context Protocol",
      "Title": "Update on the next MCP protocol release",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-09-26-mcp-next-version-update/",
      "Version": "2025-11-25",
      "Historical claim supported": "RC date and 14-day validation process.",
      "Durability": "DURABLE",
      "Claim supported": "RC date and 14-day validation process.",
      "Research packages": "1"
    },
    {
      "ID": "S053",
      "Date": "2026-05-21",
      "Source type": "RELEASE_CANDIDATE",
      "Organization": "Model Context Protocol",
      "Title": "The 2026-07-28 specification release candidate",
      "URL": "https://blog.modelcontextprotocol.io/posts/2026-07-28-release-candidate/",
      "Version": "2026-07-28-rc",
      "Historical claim supported": "RC chronology and rationale for stateless core, extensions, tasks, apps, and deprecation.",
      "Durability": "DURABLE",
      "Claim supported": "RC chronology and rationale for stateless core, extensions, tasks, apps, and deprecation. RC date, validation window, motivations and distinction between RC and GA. RC chronology and technical motivation for stateless architecture Infrastructure motivation for statelessness, routing and caching Release-candidate chronology and before/after architecture rationale.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Official project"
    },
    {
      "ID": "S054",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "MCP specification 2026-07-28",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28",
      "Version": "2026-07-28",
      "Historical claim supported": "Current authoritative specification at verification date.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current authoritative specification at verification date. Current authoritative protocol overview, roles, JSON-RPC basis, primitives, security principles.",
      "Research packages": "1,2"
    },
    {
      "ID": "S055",
      "Date": "2026-07-28",
      "Source type": "CHANGELOG",
      "Organization": "Model Context Protocol",
      "Title": "Key changes 2026-07-28",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/changelog",
      "Version": "2026-07-28",
      "Historical claim supported": "Stateless core, discovery, MRTR, subscriptions/listen, routing headers, caching, tasks extension, deprecations.",
      "Durability": "DURABLE",
      "Claim supported": "Stateless core, discovery, MRTR, subscriptions/listen, routing headers, caching, tasks extension, deprecations. Removal of handshake and sessions; discovery, subscriptions, routing, caching, extensions and deprecations. Canonical list of 2026 additions, removals, deprecations and compatibility effects Stateless core, removal of sessions and initialization, routing headers, cache scope, auth hardening, MRTR and deprecations Removal of initialize, initialized, protocol sessions and Mcp-Session-Id; addition of server/discover, MRTR, routing headers and cacheable results.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S056",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Versioning and compatibility 2026-07-28",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/versioning",
      "Version": "2026-07-28",
      "Historical claim supported": "Modern/legacy/dual-era compatibility and per-request versioning.",
      "Durability": "DURABLE",
      "Claim supported": "Modern/legacy/dual-era compatibility and per-request versioning. Current version declaration and compatibility behavior Per-request version declaration, modern versus legacy eras, discovery and dual-era compatibility.",
      "Research packages": "1,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S057",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Transports overview 2026-07-28",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/transports",
      "Version": "2026-07-28",
      "Historical claim supported": "Current transport bindings and no server-initiated JSON-RPC requests in modern core.",
      "Durability": "DURABLE",
      "Claim supported": "Current transport bindings and no server-initiated JSON-RPC requests in modern core. Current stdio and Streamable HTTP semantics Current sessionless HTTP transport and request header rules Transport is separate from protocol semantics; current stdio and Streamable HTTP transports.",
      "Research packages": "1,3,4,5",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S058",
      "Date": "2026-07-28",
      "Source type": "BLOG",
      "Organization": "Model Context Protocol",
      "Title": "The 2026-07-28 Specification",
      "URL": "https://blog.modelcontextprotocol.io/posts/2026-07-28/",
      "Version": "2026-07-28",
      "Historical claim supported": "GA announcement, SDK support, architecture rationale, download claims.",
      "Durability": "PERIODICALLY REVIEW",
      "Claim supported": "GA announcement, SDK support, architecture rationale, download claims. GA announcement and maintainer explanation of the stateless revision. GA release, stateless core, MRTR, routing, caching, auth and extensions Maintainer explanation of the current release GA announcement and maintainers’ explanation of stateless architecture, discovery, MRTR, caching and extensions.",
      "Research packages": "1,2,3,4,5",
      "Authority": "Official project"
    },
    {
      "ID": "S059",
      "Date": "2026-01-26",
      "Source type": "EXTENSION",
      "Organization": "Model Context Protocol",
      "Title": "MCP Apps: Bringing UI capabilities to MCP clients",
      "URL": "https://blog.modelcontextprotocol.io/posts/2026-01-26-mcp-apps/",
      "Version": "io.modelcontextprotocol/ui",
      "Historical claim supported": "First official extension; sandboxed server-provided UI.",
      "Durability": "DURABLE",
      "Claim supported": "First official extension; sandboxed server-provided UI. Launch of the first official MCP extension and historical context. MCP Apps origin and server-provided UI concept",
      "Research packages": "1,2,3",
      "Authority": "Official project"
    },
    {
      "ID": "S060",
      "Date": "2026-07-28",
      "Source type": "SEP",
      "Organization": "Model Context Protocol",
      "Title": "SEP-2663: Tasks extension",
      "URL": "https://modelcontextprotocol.io/seps/2663-tasks-extension",
      "Version": "io.modelcontextprotocol/tasks",
      "Historical claim supported": "Tasks moved from experimental core to official extension.",
      "Durability": "DURABLE",
      "Claim supported": "Tasks moved from experimental core to official extension. Migration of Tasks from experimental core into an official extension.",
      "Research packages": "1,2"
    },
    {
      "ID": "S061",
      "Date": "2026-07-28",
      "Source type": "SEP",
      "Organization": "Model Context Protocol",
      "Title": "SEP-2575: Stateless protocol",
      "URL": "https://modelcontextprotocol.io/seps/2575-stateless-mcp",
      "Version": "2026-07-28",
      "Historical claim supported": "Removal of handshake/sessions and per-request metadata model.",
      "Durability": "DURABLE",
      "Claim supported": "Removal of handshake/sessions and per-request metadata model. Motivation and proposal history for removing initialization state.",
      "Research packages": "1,5"
    },
    {
      "ID": "S062",
      "Date": "2026-07-28",
      "Source type": "SEP",
      "Organization": "Model Context Protocol",
      "Title": "SEP-2322: Multi Round-Trip Requests",
      "URL": "https://modelcontextprotocol.io/seps/2322-multi-round-trip-requests",
      "Version": "2026-07-28",
      "Historical claim supported": "InputRequiredResult retry pattern.",
      "Durability": "DURABLE",
      "Claim supported": "InputRequiredResult retry pattern.",
      "Research packages": "1"
    },
    {
      "ID": "S063",
      "Date": "2026-06-18",
      "Source type": "EXTENSION",
      "Organization": "Model Context Protocol",
      "Title": "Enterprise-Managed Authorization: Zero-touch OAuth for MCP",
      "URL": "https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/",
      "Version": "EMA",
      "Historical claim supported": "Stable enterprise authorization extension.",
      "Durability": "PERIODICALLY REVIEW",
      "Claim supported": "Stable enterprise authorization extension.",
      "Research packages": "1"
    },
    {
      "ID": "S064",
      "Date": "2026-08-22",
      "Source type": "ROADMAP",
      "Organization": "Model Context Protocol",
      "Title": "The New MCP Roadmap",
      "URL": "https://blog.modelcontextprotocol.io/posts/mcp-roadmap/",
      "Version": "Post-2026-07-28",
      "Historical claim supported": "Post-2026-07-28 priorities; proposals, not shipped features.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Post-2026-07-28 priorities; proposals, not shipped features. Current roadmap priorities; proposals are not shipped features. Agent identity, enterprise-ready security and HTTP hardening priorities Current roadmap and retrospective confirmation of session and handshake removal.",
      "Research packages": "1,2,4,5",
      "Authority": "Official project blog"
    },
    {
      "ID": "S065",
      "Date": "2026-07-28",
      "Source type": "POLICY",
      "Organization": "Model Context Protocol",
      "Title": "Feature lifecycle and deprecation policy",
      "URL": "https://modelcontextprotocol.io/community/feature-lifecycle",
      "Version": "",
      "Historical claim supported": "Active, Deprecated, Removed states and minimum deprecation window.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Active, Deprecated, Removed states and minimum deprecation window.",
      "Research packages": "1"
    },
    {
      "ID": "S066",
      "Date": "2025-09-08",
      "Source type": "REGISTRY",
      "Organization": "Model Context Protocol",
      "Title": "Introducing the MCP Registry",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-09-08-mcp-registry-preview/",
      "Version": "Registry preview",
      "Historical claim supported": "Official registry preview launch and origin history.",
      "Durability": "DURABLE",
      "Claim supported": "Official registry preview launch and origin history. Registry launch date, preview status and collaborative origin. Registry launch, namespace verification and metadata role",
      "Research packages": "1,2,4",
      "Authority": "Official project blog"
    },
    {
      "ID": "S067",
      "Date": "LIVE",
      "Source type": "REGISTRY",
      "Organization": "Model Context Protocol",
      "Title": "The MCP Registry: About",
      "URL": "https://modelcontextprotocol.io/registry/about",
      "Version": "Current",
      "Historical claim supported": "Current preview status, metadata role, namespaces, package-registry relationship, scanning limits.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current preview status, metadata role, namespaces, package-registry relationship, scanning limits. Official registry scope, metadata role, namespace verification and security-scanning limits. Registry metadata role and limits; code/package scanning delegated elsewhere",
      "Research packages": "1,2,4",
      "Authority": "Official docs"
    },
    {
      "ID": "S068",
      "Date": "LIVE",
      "Source type": "REGISTRY",
      "Organization": "Model Context Protocol",
      "Title": "MCP Registry",
      "URL": "https://registry.modelcontextprotocol.io/",
      "Version": "",
      "Historical claim supported": "Current registry endpoint.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current registry endpoint.",
      "Research packages": "1"
    },
    {
      "ID": "S069",
      "Date": "2025-07-31",
      "Source type": "GOVERNANCE",
      "Organization": "Model Context Protocol",
      "Title": "Building to Last: A New Governance Model for MCP",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-07-31-governance-for-mcp/",
      "Version": "",
      "Historical claim supported": "SEP process and maintainer roles.",
      "Durability": "DURABLE",
      "Claim supported": "SEP process and maintainer roles. Formal governance roles and SEP process.",
      "Research packages": "1,2"
    },
    {
      "ID": "S070",
      "Date": "2025-12-09",
      "Source type": "GOVERNANCE",
      "Organization": "Model Context Protocol",
      "Title": "MCP joins the Agentic AI Foundation",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-12-09-mcp-joins-agentic-ai-foundation/",
      "Version": "",
      "Historical claim supported": "Donation to AAIF, technical autonomy, project-reported adoption statistics.",
      "Durability": "DURABLE",
      "Claim supported": "Donation to AAIF, technical autonomy, project-reported adoption statistics. MCP's Linux Foundation/AAIF organizational home and retained technical governance.",
      "Research packages": "1,2"
    },
    {
      "ID": "S071",
      "Date": "LIVE",
      "Source type": "GOVERNANCE",
      "Organization": "Model Context Protocol",
      "Title": "Governance and stewardship",
      "URL": "https://modelcontextprotocol.io/community/governance",
      "Version": "",
      "Historical claim supported": "Current lead/core maintainer structure and LF project status.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current lead/core maintainer structure and LF project status. Current maintainer structure and individual rather than corporate membership.",
      "Research packages": "1,2"
    },
    {
      "ID": "S072",
      "Date": "LIVE",
      "Source type": "LICENSE",
      "Organization": "Model Context Protocol",
      "Title": "Project license and licensing transition",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/LICENSE",
      "Version": "",
      "Historical claim supported": "MIT-to-Apache-2.0 transition and CC BY 4.0 documentation license.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "MIT-to-Apache-2.0 transition and CC BY 4.0 documentation license.",
      "Research packages": "1"
    },
    {
      "ID": "S073",
      "Date": "2026-02-23",
      "Source type": "GOVERNANCE",
      "Organization": "Model Context Protocol",
      "Title": "SDK Tiering System",
      "URL": "https://modelcontextprotocol.io/community/sdk-tiers",
      "Version": "",
      "Historical claim supported": "Tier 1–3 requirements and conformance-based governance.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Tier 1–3 requirements and conformance-based governance. Meaning of SDK tiers and maintenance/conformance expectations.",
      "Research packages": "1,2"
    },
    {
      "ID": "S074",
      "Date": "2026-01-15",
      "Source type": "SEP",
      "Organization": "Model Context Protocol",
      "Title": "SEP-2148: MCP Contributor Ladder",
      "URL": "https://modelcontextprotocol.io/seps/2148-contributor-ladder",
      "Version": "",
      "Historical claim supported": "Contributor progression and governance transparency.",
      "Durability": "DURABLE",
      "Claim supported": "Contributor progression and governance transparency.",
      "Research packages": "1"
    },
    {
      "ID": "S075",
      "Date": "2024-11-25",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "TypeScript SDK repository",
      "URL": "https://github.com/modelcontextprotocol/typescript-sdk",
      "Version": "",
      "Historical claim supported": "Official launch SDK; current status live-check.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official launch SDK; current status live-check.",
      "Research packages": "1"
    },
    {
      "ID": "S076",
      "Date": "2024-11-25",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Python SDK repository",
      "URL": "https://github.com/modelcontextprotocol/python-sdk",
      "Version": "",
      "Historical claim supported": "Official launch SDK; current status live-check.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official launch SDK; current status live-check.",
      "Research packages": "1"
    },
    {
      "ID": "S077",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Go SDK repository",
      "URL": "https://github.com/modelcontextprotocol/go-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S078",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "C# SDK repository",
      "URL": "https://github.com/modelcontextprotocol/csharp-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S079",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Java SDK repository",
      "URL": "https://github.com/modelcontextprotocol/java-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S080",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Kotlin SDK repository",
      "URL": "https://github.com/modelcontextprotocol/kotlin-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S081",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Rust SDK repository",
      "URL": "https://github.com/modelcontextprotocol/rust-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S082",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Swift SDK repository",
      "URL": "https://github.com/modelcontextprotocol/swift-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S083",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "Ruby SDK repository",
      "URL": "https://github.com/modelcontextprotocol/ruby-sdk",
      "Version": "",
      "Historical claim supported": "Official SDK status and history.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official SDK status and history.",
      "Research packages": "1"
    },
    {
      "ID": "S084",
      "Date": "2026-07-27",
      "Source type": "SDK_RELEASE",
      "Organization": "Model Context Protocol",
      "Title": "The Official Ruby SDK for MCP Reaches 1.0",
      "URL": "https://blog.modelcontextprotocol.io/posts/ruby-sdk-1-0/",
      "Version": "",
      "Historical claim supported": "Ruby 1.0 and Tier 2 milestone.",
      "Durability": "DURABLE",
      "Claim supported": "Ruby 1.0 and Tier 2 milestone.",
      "Research packages": "1"
    },
    {
      "ID": "S085",
      "Date": "2025-09-05",
      "Source type": "SDK_RELEASE",
      "Organization": "Model Context Protocol",
      "Title": "Announcing the Official PHP SDK for MCP",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-09-05-php-sdk/",
      "Version": "",
      "Historical claim supported": "PHP official GA announcement and initial server-only scope.",
      "Durability": "DURABLE",
      "Claim supported": "PHP official GA announcement and initial server-only scope.",
      "Research packages": "1"
    },
    {
      "ID": "S086",
      "Date": "LIVE",
      "Source type": "SDK",
      "Organization": "Model Context Protocol",
      "Title": "PHP SDK repository",
      "URL": "https://github.com/modelcontextprotocol/php-sdk",
      "Version": "",
      "Historical claim supported": "Current official PHP SDK status.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current official PHP SDK status.",
      "Research packages": "1"
    },
    {
      "ID": "S087",
      "Date": "2025-04-07",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Microsoft / Visual Studio Code",
      "Title": "Agent mode: available to all users and supports MCP",
      "URL": "https://code.visualstudio.com/blogs/2025/04/07/agentMode",
      "Version": "",
      "Historical claim supported": "Official VS Code MCP host/client support and LSP influence statement.",
      "Durability": "DURABLE",
      "Claim supported": "Official VS Code MCP host/client support and LSP influence statement. Initial official VS Code MCP host support.",
      "Research packages": "1,2"
    },
    {
      "ID": "S088",
      "Date": "2025-05-14",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Microsoft / Visual Studio Code",
      "Title": "Beyond the tools, adding MCP in VS Code",
      "URL": "https://code.visualstudio.com/blogs/2025/05/12/agent-mode-meets-mcp",
      "Version": "",
      "Historical claim supported": "Expansion from tools toward richer capabilities and installation UX.",
      "Durability": "DURABLE",
      "Claim supported": "Expansion from tools toward richer capabilities and installation UX. VS Code host behavior, tool picker and server integration.",
      "Research packages": "1,5",
      "Notes": "First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map."
    },
    {
      "ID": "S089",
      "Date": "2025-05-21",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "OpenAI",
      "Title": "New tools and features in the Responses API",
      "URL": "https://openai.com/index/new-tools-and-features-in-the-responses-api/",
      "Version": "",
      "Historical claim supported": "First unequivocal official remote MCP support in OpenAI API product.",
      "Durability": "DURABLE",
      "Claim supported": "First unequivocal official remote MCP support in OpenAI API product. Official remote MCP support in the Responses API. First official OpenAI remote MCP support announcement",
      "Research packages": "1,2,3",
      "Authority": "Primary vendor"
    },
    {
      "ID": "S090",
      "Date": "LIVE",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "OpenAI",
      "Title": "Model Context Protocol in the OpenAI Agents SDK",
      "URL": "https://openai.github.io/openai-agents-python/mcp/",
      "Version": "",
      "Historical claim supported": "Current hosted, Streamable HTTP, SSE, and stdio MCP integration modes.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current hosted, Streamable HTTP, SSE, and stdio MCP integration modes. MCP schema conversion, name prefixing, hosted/local transport, filtering, approvals and caching Hosted, Streamable HTTP, legacy SSE and stdio MCP client options; manager for multiple servers.",
      "Research packages": "1,3,5",
      "Authority": "Official SDK"
    },
    {
      "ID": "S091",
      "Date": "2025-04-01",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Amazon Web Services",
      "Title": "Introducing AWS MCP Servers for code assistants, Part 1",
      "URL": "https://aws.amazon.com/blogs/machine-learning/introducing-aws-mcp-servers-for-code-assistants-part-1/",
      "Version": "",
      "Historical claim supported": "Official open-source AWS server suite.",
      "Durability": "DURABLE",
      "Claim supported": "Official open-source AWS server suite. Official AWS server suite adoption.",
      "Research packages": "1,2"
    },
    {
      "ID": "S092",
      "Date": "2025-04-22",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Google Cloud",
      "Title": "MCP Toolbox for Databases supports MCP",
      "URL": "https://cloud.google.com/blog/products/ai-machine-learning/mcp-toolbox-for-databases-now-supports-model-context-protocol/",
      "Version": "",
      "Historical claim supported": "Official Google Cloud server/platform support.",
      "Durability": "DURABLE",
      "Claim supported": "Official Google Cloud server/platform support. Official Google Cloud MCP server/platform adoption.",
      "Research packages": "1,2"
    },
    {
      "ID": "S093",
      "Date": "2025-03-25",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Cloudflare",
      "Title": "Build and deploy remote MCP servers to Cloudflare",
      "URL": "https://blog.cloudflare.com/remote-model-context-protocol-servers-mcp/",
      "Version": "",
      "Historical claim supported": "Remote hosting, OAuth provider, and Agents SDK support.",
      "Durability": "DURABLE",
      "Claim supported": "Remote hosting, OAuth provider, and Agents SDK support. Early official remote MCP hosting and OAuth infrastructure.",
      "Research packages": "1,2"
    },
    {
      "ID": "S094",
      "Date": "2025-04-30",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Cloudflare",
      "Title": "Streamable HTTP and Python support for MCP servers",
      "URL": "https://blog.cloudflare.com/streamable-http-mcp-servers-python/",
      "Version": "",
      "Historical claim supported": "Rapid transport adoption and dual-transport migration.",
      "Durability": "DURABLE",
      "Claim supported": "Rapid transport adoption and dual-transport migration.",
      "Research packages": "1"
    },
    {
      "ID": "S095",
      "Date": "2025-05-01",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Cloudflare",
      "Title": "Thirteen new MCP servers from Cloudflare",
      "URL": "https://blog.cloudflare.com/thirteen-new-mcp-servers-from-cloudflare/",
      "Version": "",
      "Historical claim supported": "Official managed remote servers.",
      "Durability": "DURABLE",
      "Claim supported": "Official managed remote servers.",
      "Research packages": "1"
    },
    {
      "ID": "S096",
      "Date": "2025-05-01",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Cloudflare and vendors",
      "Title": "MCP Demo Day",
      "URL": "https://blog.cloudflare.com/mcp-demo-day/",
      "Version": "",
      "Historical claim supported": "Remote servers from multiple SaaS vendors; useful but partly promotional.",
      "Durability": "PERIODICALLY REVIEW",
      "Claim supported": "Remote servers from multiple SaaS vendors; useful but partly promotional.",
      "Research packages": "1"
    },
    {
      "ID": "S097",
      "Date": "2025-05-01",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Atlassian",
      "Title": "Atlassian Remote MCP Server beta",
      "URL": "https://www.atlassian.com/blog/announcements/remote-mcp-server",
      "Version": "",
      "Historical claim supported": "Official Atlassian remote-server beta.",
      "Durability": "DURABLE",
      "Claim supported": "Official Atlassian remote-server beta.",
      "Research packages": "1"
    },
    {
      "ID": "S098",
      "Date": "LIVE",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "GitHub",
      "Title": "GitHub MCP Server repository",
      "URL": "https://github.com/github/github-mcp-server",
      "Version": "",
      "Historical claim supported": "Official GitHub server implementation.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official GitHub server implementation.",
      "Research packages": "1"
    },
    {
      "ID": "S099",
      "Date": "2025-09-04",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "GitHub",
      "Title": "GitHub MCP Server generally available",
      "URL": "https://github.blog/changelog/2025-09-04-github-mcp-server-is-now-generally-available/",
      "Version": "",
      "Historical claim supported": "Official remote server GA and authorization model.",
      "Durability": "DURABLE",
      "Claim supported": "Official remote server GA and authorization model.",
      "Research packages": "1"
    },
    {
      "ID": "S100",
      "Date": "LIVE",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Cursor",
      "Title": "Cursor MCP documentation",
      "URL": "https://docs.cursor.com/context/model-context-protocol",
      "Version": "",
      "Historical claim supported": "Current host support; first historical date remains separately qualified.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Current host support; first historical date remains separately qualified.",
      "Research packages": "1"
    },
    {
      "ID": "S101",
      "Date": "2025-04-15",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Cursor",
      "Title": "Cursor changelog: MCP image support",
      "URL": "https://www.cursor.com/changelog/0-48",
      "Version": "",
      "Historical claim supported": "Early dated Cursor MCP capability evidence.",
      "Durability": "DURABLE",
      "Claim supported": "Early dated Cursor MCP capability evidence.",
      "Research packages": "1"
    },
    {
      "ID": "S102",
      "Date": "2025-05",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "JetBrains",
      "Title": "MCP support in IntelliJ IDEA 2025.1",
      "URL": "https://blog.jetbrains.com/idea/2025/05/mcp-support-in-intellij-idea/",
      "Version": "",
      "Historical claim supported": "Official JetBrains host/client support.",
      "Durability": "DURABLE",
      "Claim supported": "Official JetBrains host/client support.",
      "Research packages": "1"
    },
    {
      "ID": "S103",
      "Date": "LIVE",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Notion",
      "Title": "Notion MCP documentation",
      "URL": "https://developers.notion.com/docs/mcp",
      "Version": "",
      "Historical claim supported": "Official Notion server documentation; current state live-check.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Official Notion server documentation; current state live-check.",
      "Research packages": "1"
    },
    {
      "ID": "S104",
      "Date": "LIVE",
      "Source type": "FRAMEWORK",
      "Organization": "LangChain",
      "Title": "LangChain MCP adapters",
      "URL": "https://docs.langchain.com/oss/python/langchain/mcp",
      "Version": "",
      "Historical claim supported": "Framework adapter demonstrating MCP-to-native-tool mapping.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Framework adapter demonstrating MCP-to-native-tool mapping.",
      "Research packages": "1"
    },
    {
      "ID": "S105",
      "Date": "LIVE",
      "Source type": "FRAMEWORK",
      "Organization": "LlamaIndex",
      "Title": "MCP integration guide",
      "URL": "https://developers.llamaindex.ai/python/examples/tools/mcp/",
      "Version": "",
      "Historical claim supported": "Framework integration.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "Framework integration.",
      "Research packages": "1"
    },
    {
      "ID": "S106",
      "Date": "LIVE",
      "Source type": "FRAMEWORK",
      "Organization": "Microsoft",
      "Title": "Semantic Kernel MCP documentation",
      "URL": "https://learn.microsoft.com/en-us/semantic-kernel/concepts/plugins/adding-mcp-plugins",
      "Version": "",
      "Historical claim supported": "MCP adaptation into Semantic Kernel plugin abstraction.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "MCP adaptation into Semantic Kernel plugin abstraction.",
      "Research packages": "1"
    },
    {
      "ID": "S107",
      "Date": "LIVE",
      "Source type": "FRAMEWORK",
      "Organization": "Microsoft",
      "Title": "AutoGen MCP Workbench",
      "URL": "https://microsoft.github.io/autogen/stable/reference/python/autogen_ext.tools.mcp.html",
      "Version": "",
      "Historical claim supported": "MCP integration in AutoGen.",
      "Durability": "LIVE-CHECK REQUIRED",
      "Claim supported": "MCP integration in AutoGen.",
      "Research packages": "1"
    },
    {
      "ID": "S108",
      "Date": "2025-04-01",
      "Source type": "SECURITY",
      "Organization": "Invariant Labs",
      "Title": "MCP Security Notification: Tool Poisoning Attacks",
      "URL": "https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks",
      "Version": "Session-era clients",
      "Historical claim supported": "Canonical disclosure of hidden tool-description attacks, rug pulls, and tool shadowing.",
      "Durability": "DURABLE",
      "Claim supported": "Canonical disclosure of hidden tool-description attacks, rug pulls, and tool shadowing. Original tool-poisoning, rug-pull and cross-server-shadowing research. Original public disclosure of tool poisoning, shadowing and rug-pull patterns",
      "Research packages": "1,2,4",
      "Authority": "Original research"
    },
    {
      "ID": "S109",
      "Date": "2025-06-13",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "MCP Inspector missing authentication",
      "URL": "https://github.com/advisories/GHSA-7f8r-222p-6f5g",
      "Version": "<0.14.1",
      "Historical claim supported": "Inspector proxy exposure; implementation vulnerability, not core-protocol semantics.",
      "Durability": "DURABLE",
      "Claim supported": "Inspector proxy exposure; implementation vulnerability, not core-protocol semantics. Representative host/developer-tool implementation vulnerability. Remote code execution due to unauthenticated Inspector proxy; patched/fixed status: 0.14.1",
      "Research packages": "1,2,4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/developer tool. Verify current affected and fixed ranges before publication."
    },
    {
      "ID": "S110",
      "Date": "2025-09-06",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "MCP Inspector XSS advisory",
      "URL": "https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-g9hg-qhmf-q45m",
      "Version": "<0.16.6",
      "Historical claim supported": "Inspector implementation vulnerability with potential command-execution path.",
      "Durability": "DURABLE",
      "Claim supported": "Inspector implementation vulnerability with potential command-execution path. Representative Inspector UI vulnerability and patch boundary. Cross-site scripting in Inspector; patched/fixed status: 0.16.6",
      "Research packages": "1,2,4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/developer tool. Verify current affected and fixed ranges before publication."
    },
    {
      "ID": "S111",
      "Date": "2025-12-02",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "TypeScript SDK DNS rebinding advisory",
      "URL": "https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-w48q-cv73-mx4w",
      "Version": "<1.24.0",
      "Historical claim supported": "HTTP SDK default-binding risk; stdio unaffected.",
      "Durability": "DURABLE",
      "Claim supported": "HTTP SDK default-binding risk; stdio unaffected. Representative local HTTP SDK exposure and Origin/bind protection. DNS rebinding protection disabled by default for unauthenticated localhost HTTP servers; patched/fixed status: 1.24.0",
      "Research packages": "1,2,4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication."
    },
    {
      "ID": "S112",
      "Date": "2025-12-02",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "Python SDK DNS rebinding advisory",
      "URL": "https://github.com/advisories/GHSA-9h52-p55h-vw2f",
      "Version": "<1.23.0",
      "Historical claim supported": "Python HTTP SDK default-binding risk.",
      "Durability": "DURABLE",
      "Claim supported": "Python HTTP SDK default-binding risk. Representative Python SDK DNS-rebinding vulnerability. DNS rebinding protection disabled by default for localhost HTTP servers; patched/fixed status: 1.23.0",
      "Research packages": "1,2,4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication."
    },
    {
      "ID": "S113",
      "Date": "2025-07-04",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "Python FastMCP validation denial of service",
      "URL": "https://github.com/advisories/GHSA-3q26-8f7c-rv6m",
      "Version": "",
      "Historical claim supported": "SDK validation resource-exhaustion issue.",
      "Durability": "DURABLE",
      "Claim supported": "SDK validation resource-exhaustion issue.",
      "Research packages": "1"
    },
    {
      "ID": "S114",
      "Date": "2026-01-07",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "TypeScript UriTemplate ReDoS advisory",
      "URL": "https://github.com/modelcontextprotocol/typescript-sdk/security/advisories/GHSA-8r9q-7v3x-65wq",
      "Version": "",
      "Historical claim supported": "SDK parsing/regular-expression vulnerability.",
      "Durability": "DURABLE",
      "Claim supported": "SDK parsing/regular-expression vulnerability.",
      "Research packages": "1"
    },
    {
      "ID": "S115",
      "Date": "2026-04-07",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Model Context Protocol",
      "Title": "Java SDK DNS rebinding advisory",
      "URL": "https://github.com/advisories/GHSA-27c6-wj9q-3v3m",
      "Version": "",
      "Historical claim supported": "Java SDK HTTP exposure hardening.",
      "Durability": "DURABLE",
      "Claim supported": "Java SDK HTTP exposure hardening.",
      "Research packages": "1"
    },
    {
      "ID": "S116",
      "Date": "2025",
      "Source type": "RESEARCH",
      "Organization": "Academic researchers",
      "Title": "MCPTox: A Benchmark for Tool Poisoning Attacks",
      "URL": "https://arxiv.org/abs/2508.14925",
      "Version": "",
      "Historical claim supported": "Academic evaluation of malicious MCP tool metadata and behavior.",
      "Durability": "PERIODICALLY REVIEW",
      "Claim supported": "Academic evaluation of malicious MCP tool metadata and behavior.",
      "Research packages": "1"
    },
    {
      "ID": "S117",
      "Date": "2025",
      "Source type": "RESEARCH",
      "Organization": "Academic researchers",
      "Title": "Mind Your Server: A Systematic Study of MCP Security",
      "URL": "https://arxiv.org/abs/2509.17944",
      "Version": "",
      "Historical claim supported": "Broader empirical MCP security analysis.",
      "Durability": "PERIODICALLY REVIEW",
      "Claim supported": "Broader empirical MCP security analysis.",
      "Research packages": "1"
    },
    {
      "ID": "S118",
      "Date": "2025-04-09",
      "Source type": "PROTOCOL",
      "Organization": "Google",
      "Title": "A2A: A new era of agent interoperability",
      "URL": "https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/",
      "Version": "",
      "Historical claim supported": "Agent-to-agent protocol launch and complementary positioning to MCP.",
      "Durability": "DURABLE",
      "Claim supported": "Agent-to-agent protocol launch and complementary positioning to MCP.",
      "Research packages": "1"
    },
    {
      "ID": "S119",
      "Date": "2025-06-23",
      "Source type": "GOVERNANCE",
      "Organization": "Linux Foundation",
      "Title": "Linux Foundation launches the Agent2Agent Protocol project",
      "URL": "https://www.linuxfoundation.org/press/linux-foundation-launches-the-agent2agent-protocol-project-to-enable-secure-intelligent-communication-between-ai-agents",
      "Version": "",
      "Historical claim supported": "A2A governance transition.",
      "Durability": "DURABLE",
      "Claim supported": "A2A governance transition.",
      "Research packages": "1"
    },
    {
      "ID": "S120",
      "Date": "2025-03-17",
      "Source type": "PROTOCOL",
      "Organization": "IBM",
      "Title": "Introducing the Agent Communication Protocol",
      "URL": "https://www.ibm.com/think/topics/agent-communication-protocol",
      "Version": "",
      "Historical claim supported": "ACP as an agent-to-agent protocol, not an MCP substitute at the same layer.",
      "Durability": "DURABLE",
      "Claim supported": "ACP as an agent-to-agent protocol, not an MCP substitute at the same layer.",
      "Research packages": "1"
    },
    {
      "ID": "S121",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Architecture 2026-07-28",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/architecture",
      "Version": "2026-07-28",
      "Claim supported": "Current host, client, server definitions; one client per server; stateless per-request model. Current host, client, and server definitions; one host manages multiple clients; each client relates to one server; stateless per-request architecture.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "DURABLE"
    },
    {
      "ID": "S122",
      "Date": "2026-07-28",
      "Source type": "DOCUMENTATION",
      "Organization": "Model Context Protocol",
      "Title": "MCP Architecture Guide",
      "URL": "https://modelcontextprotocol.io/docs/2026-07-28/learn/architecture",
      "Version": "2026-07-28",
      "Claim supported": "Conceptual architecture, data and transport layers, local and remote servers.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S123",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tools",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/server/tools",
      "Version": "2026-07-28",
      "Claim supported": "Tool discovery, schemas, invocation, result content, structured output, annotations and security rules. Current tool schemas, calls, results, annotations and state-handle guidance Current tool semantics, annotations, schemas, explicit handles and security considerations Tool discovery and invocation, host human-in-the-loop guidance, annotations, explicit handles and MRTR.",
      "Historical claim supported": "",
      "Research packages": "2,3,4,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S124",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Resources",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/server/resources",
      "Version": "2026-07-28",
      "Claim supported": "URI-identified resources, list/read/templates and subscriptions behavior. Current resource primitive Server-exposed resources, URI identification, list/read behavior and subscriptions.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S125",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Prompts",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/server/prompts",
      "Version": "2026-07-28",
      "Claim supported": "Protocol-exposed prompt templates, arguments, list/get behavior and user control. Current prompt primitive Server-exposed prompt templates and host presentation.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S126",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Elicitation",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/client/elicitation",
      "Version": "2026-07-28",
      "Claim supported": "Server requests for user input, form and URL modes, restrictions on sensitive data. Current client-side elicitation through MRTR and host-controlled user interaction.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "DURABLE"
    },
    {
      "ID": "S127",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Server discovery",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/server/discover",
      "Version": "2026-07-28",
      "Claim supported": "Mandatory server/discover implementation and optional client invocation for versions and capabilities. Optional sessionless capability and version discovery server/discover semantics, supported versions and capabilities, optional client use, self-reported identity caveat.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S128",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Caching",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/server/utilities/caching",
      "Version": "2026-07-28",
      "Claim supported": "Cache hints and scope for complete list/read/discovery results.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S129",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Multi Round-Trip Requests",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/patterns/mrtr",
      "Version": "2026-07-28",
      "Claim supported": "Current mechanism for additional client input without server-initiated JSON-RPC requests.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S130",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Base protocol overview",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic",
      "Version": "2026-07-28",
      "Claim supported": "JSON-RPC messages, current statelessness, explicit state identifiers and authorization applicability. Current JSON-RPC base messages and request metadata JSON-RPC basis, current message directions, requests, responses, notifications and result types.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S131",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Streamable HTTP",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/transports/streamable-http",
      "Version": "2026-07-28",
      "Claim supported": "Current remote transport, one POST endpoint, optional request-scoped SSE, routing headers and security. Current single-endpoint HTTP behavior, removal of GET stream and protocol sessions, request-scoped SSE, Origin requirements.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "DURABLE"
    },
    {
      "ID": "S132",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "stdio transport",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/transports/stdio",
      "Version": "2026-07-28",
      "Claim supported": "Local subprocess transport, newline-delimited JSON-RPC and stdout/stderr requirements. Local subprocess lifecycle, stdin/stdout framing, stderr logging, shutdown and restart behavior.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "DURABLE"
    },
    {
      "ID": "S133",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Authorization",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization",
      "Version": "2026-07-28",
      "Claim supported": "Current HTTP authorization framework, OAuth resource-server roles, protected resource metadata and resource indicators. Current HTTP authorization roles, metadata, issuer validation, Resource Indicators, token handling and CIMD preference",
      "Historical claim supported": "",
      "Research packages": "2,4",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S134",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "SECURITY_GUIDANCE",
      "Organization": "Model Context Protocol",
      "Title": "Security Best Practices",
      "URL": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
      "Version": "2026-07-28",
      "Claim supported": "Confused deputy, token passthrough, SSRF, state handles, stdio proxy, redirect and issuer security. Layered security guidance, token handling and deployment risks Current official guidance on confused deputy, token passthrough, SSRF, local servers, state handles and OAuth URLs",
      "Historical claim supported": "",
      "Research packages": "2,3,4",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Official project"
    },
    {
      "ID": "S135",
      "Date": "2026-07-28",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Deprecated Features",
      "URL": "https://modelcontextprotocol.io/specification/2026-07-28/deprecated",
      "Version": "2026-07-28",
      "Claim supported": "Roots, sampling, logging, DCR and HTTP+SSE deprecation status and migration paths.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S136",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "EXTENSION",
      "Organization": "Model Context Protocol",
      "Title": "MCP Apps",
      "URL": "https://modelcontextprotocol.io/extensions/apps/overview",
      "Version": "io.modelcontextprotocol/ui",
      "Claim supported": "Interactive HTML interfaces, tool-linked UI resources, sandbox and host support variability. Server-provided interactive UI, sandboxing and host security boundary",
      "Historical claim supported": "",
      "Research packages": "2,4",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Authoritative extension docs"
    },
    {
      "ID": "S137",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "EXTENSION",
      "Organization": "Model Context Protocol",
      "Title": "Tasks",
      "URL": "https://modelcontextprotocol.io/extensions/tasks/overview",
      "Version": "io.modelcontextprotocol/tasks",
      "Claim supported": "Durable asynchronous operations, task IDs, polling, input and cancellation semantics. Long-running task handles and lifecycle semantics",
      "Historical claim supported": "",
      "Research packages": "2,4",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Authoritative extension docs"
    },
    {
      "ID": "S138",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "SDK_INDEX",
      "Organization": "Model Context Protocol",
      "Title": "Official MCP SDKs",
      "URL": "https://modelcontextprotocol.io/docs/2026-07-28/sdk",
      "Version": "Current",
      "Claim supported": "Current official SDK list and tier assignments.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S139",
      "Date": "LIVE",
      "Source type": "DOCUMENTATION",
      "Organization": "Microsoft",
      "Title": "Language Server Extension Guide",
      "URL": "https://code.visualstudio.com/api/language-extensions/language-server-extension-guide",
      "Version": "Current",
      "Claim supported": "LSP client/server architecture and the M × N integration problem.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S140",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "OpenAI",
      "Title": "Developer mode and MCP apps in ChatGPT",
      "URL": "https://help.openai.com/en/articles/12584461-developer-mode-and-full-mcp-connectors-in-chatgpt",
      "Version": "Current",
      "Claim supported": "Current ChatGPT remote MCP limitations, local-server tunnel requirement and plan-dependent access. ChatGPT as a host with remote MCP connector support and MCP Apps; current availability and remote-only direct connection constraints.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "LIVE-CHECK REQUIRED",
      "Notes": "First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map."
    },
    {
      "ID": "S141",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Microsoft / Visual Studio Code",
      "Title": "Add and manage MCP servers in VS Code",
      "URL": "https://code.visualstudio.com/docs/agent-customization/mcp-servers",
      "Version": "Current",
      "Claim supported": "Current local/remote installation, trust, sandboxing, prompts/resources/apps and enterprise policy support. VS Code host/client support for tools, resources, prompts and MCP Apps; local and remote servers, trust and policy.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "LIVE-CHECK REQUIRED",
      "Notes": "First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map."
    },
    {
      "ID": "S142",
      "Date": "2025-06-12",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Microsoft / Visual Studio Code",
      "Title": "The Complete MCP Experience: Full Specification Support in VS Code",
      "URL": "https://code.visualstudio.com/blogs/2025/06/12/full-mcp-spec-support",
      "Version": "2025-era",
      "Claim supported": "Official authorization, prompts, resources and sampling adoption.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S143",
      "Date": "2026-01-26",
      "Source type": "VENDOR_ADOPTION",
      "Organization": "Microsoft / Visual Studio Code",
      "Title": "Giving Agents a Visual Voice: MCP Apps Support in VS Code",
      "URL": "https://code.visualstudio.com/blogs/2026/01/26/mcp-apps-support",
      "Version": "MCP Apps",
      "Claim supported": "Official MCP Apps host support.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "DURABLE"
    },
    {
      "ID": "S144",
      "Date": "2026-06-18",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Google",
      "Title": "MCP servers with Gemini CLI",
      "URL": "https://geminicli.com/docs/tools/mcp-server/",
      "Version": "Current",
      "Claim supported": "Gemini CLI support for stdio, legacy SSE and Streamable HTTP, tools/resources/prompts, OAuth and confirmations. Gemini CLI local and remote MCP support and host permission flow.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "LIVE-CHECK REQUIRED",
      "Notes": "First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map."
    },
    {
      "ID": "S145",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Anthropic",
      "Title": "Get started with custom connectors using remote MCP",
      "URL": "https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp",
      "Version": "Current",
      "Claim supported": "Claude custom remote MCP connector availability and trust cautions. Claude remote connector behavior and cloud-originated connections.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S146",
      "Date": "LIVE; verified 2026-08-25",
      "Source type": "VENDOR_DOCUMENTATION",
      "Organization": "Anthropic",
      "Title": "Use connectors to extend Claude's capabilities",
      "URL": "https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities",
      "Version": "Current",
      "Claim supported": "Remote connectors connect from Anthropic cloud and product terminology differs from protocol roles.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S147",
      "Date": "2026",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "GitHub Advisory Database",
      "Title": "TypeScript SDK cross-client data leak",
      "URL": "https://github.com/advisories/GHSA-345p-7cg4-v4c7",
      "Version": "TypeScript SDK 1.10.0–1.25.3",
      "Claim supported": "Representative multi-client isolation implementation defect. Cross-client response data leakage when server/transport instances are reused; patched/fixed status: 1.26.0",
      "Historical claim supported": "",
      "Research packages": "2,4",
      "Durability": "DURABLE",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/multi-tenancy. Verify current affected and fixed ranges before publication."
    },
    {
      "ID": "S148",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Creating helpful, reliable, people-first content",
      "URL": "https://developers.google.com/search/docs/fundamentals/creating-helpful-content",
      "Version": "Current",
      "Claim supported": "People-first, original, well-sourced content and no preferred word count. People-first, original, trustworthy content and authorship guidance People-first content, no preferred word count, authorship/process transparency and satisfying user intent.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Primary search-engine guidance"
    },
    {
      "ID": "S149",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Google's guidance on generative AI content",
      "URL": "https://developers.google.com/search/docs/fundamentals/using-gen-ai-content",
      "Version": "Current",
      "Claim supported": "Accuracy, quality, relevance and transparent production context.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S150",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Influencing your title links in search results",
      "URL": "https://developers.google.com/search/docs/appearance/title-link",
      "Version": "Current",
      "Claim supported": "Descriptive, concise and consistent title/H1 recommendations. Descriptive concise titles, distinctive H1 and avoidance of keyword stuffing.",
      "Historical claim supported": "",
      "Research packages": "2,5",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S151",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Introduction to structured data markup",
      "URL": "https://developers.google.com/search/docs/appearance/structured-data/intro-structured-data",
      "Version": "Current",
      "Claim supported": "Structured data implementation and validation guidance.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S152",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Article structured data",
      "URL": "https://developers.google.com/search/docs/appearance/structured-data/article",
      "Version": "Current",
      "Claim supported": "Article author, date, headline and image markup guidance. Article structured-data recommendations",
      "Historical claim supported": "",
      "Research packages": "2,3",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Primary search-engine guidance"
    },
    {
      "ID": "S153",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Breadcrumb structured data",
      "URL": "https://developers.google.com/search/docs/appearance/structured-data/breadcrumb",
      "Version": "Current",
      "Claim supported": "BreadcrumbList implementation and validation. BreadcrumbList markup guidance BreadcrumbList implementation and validation guidance.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Primary search-engine guidance"
    },
    {
      "ID": "S154",
      "Date": "2023-08-08",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Changes to HowTo and FAQ rich results",
      "URL": "https://developers.google.com/search/blog/2023/08/howto-faq-changes",
      "Version": "Current policy context",
      "Claim supported": "FAQ rich results are generally restricted to authoritative government and health sites.",
      "Historical claim supported": "",
      "Research packages": "2",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S155",
      "Date": "2026-07",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "General structured data guidelines",
      "URL": "https://developers.google.com/search/docs/appearance/structured-data/sd-policies",
      "Version": "Current",
      "Claim supported": "JSON-LD recommendation, relevance, accuracy and no guarantee of rich-result display. Accurate visible structured data and no rich-result guarantee",
      "Historical claim supported": "",
      "Research packages": "2,3",
      "Durability": "PERIODICALLY REVIEW",
      "Authority": "Primary search-engine guidance"
    },
    {
      "ID": "S156",
      "Date": "2025-03-26",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Lifecycle 2025-03-26",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26/basic/lifecycle",
      "Version": "2025-03-26",
      "Claim supported": "Initialization, protocol-version agreement, capability negotiation, initialized notification and session-era lifecycle semantics. Initialization, version and capability negotiation in March 2025 Stateful initialization and negotiated capabilities during the first Streamable HTTP era.",
      "Historical claim supported": "",
      "Research packages": "2,3,5",
      "Durability": "DURABLE",
      "Authority": "Authoritative specification"
    },
    {
      "ID": "S157",
      "Date": "2026-03-12",
      "Source type": "Protocol specification",
      "Organization": "A2A Project",
      "Title": "Agent2Agent (A2A) Protocol Specification",
      "URL": "https://a2a-protocol.org/v1.0.0/specification/",
      "Version": "1.0.0; latest released specification rechecked 2026-08-25",
      "Claim supported": "The A2A 1.0 specification defines agent discovery, messages, tasks, artifacts, versioning, security, and multiple protocol bindings.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S158",
      "Date": "2025-03-26",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tools",
      "URL": "https://modelcontextprotocol.io/specification/2025-03-26/server/tools",
      "Version": "2025-03-26",
      "Claim supported": "Tool annotations and March 2025 tool semantics Tool annotations as descriptive hints rather than guarantees",
      "Historical claim supported": "Tool annotations and March 2025 tool semantics",
      "Research packages": "3,4",
      "Authority": "Authoritative specification",
      "Durability": "DURABLE"
    },
    {
      "ID": "S159",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Lifecycle",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/basic/lifecycle",
      "Version": "2025-06-18",
      "Claim supported": "June 2025 retained initialization and sessions",
      "Historical claim supported": "June 2025 retained initialization and sessions",
      "Research packages": "3",
      "Authority": "Authoritative specification",
      "Durability": "DURABLE"
    },
    {
      "ID": "S160",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Lifecycle",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/basic/lifecycle",
      "Version": "2025-11-25",
      "Claim supported": "Last released initialization/session lifecycle before 2026 stateless core Last released handshake/session-era lifecycle before the 2026 revision.",
      "Historical claim supported": "Last released initialization/session lifecycle before 2026 stateless core",
      "Research packages": "3,5",
      "Authority": "Authoritative specification",
      "Durability": "DURABLE"
    },
    {
      "ID": "S161",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Tools",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools",
      "Version": "2025-11-25",
      "Claim supported": "November 2025 tool fields and taskSupport execution metadata",
      "Historical claim supported": "November 2025 tool fields and taskSupport execution metadata",
      "Research packages": "3",
      "Authority": "Authoritative specification",
      "Durability": "DURABLE"
    },
    {
      "ID": "S162",
      "Date": "2025-11-25",
      "Source type": "BLOG",
      "Organization": "Model Context Protocol",
      "Title": "One Year of MCP: November 2025 Spec Release",
      "URL": "https://blog.modelcontextprotocol.io/posts/2025-11-25-first-mcp-anniversary/",
      "Version": "2025-11-25",
      "Claim supported": "Official retrospective and Tasks explanation",
      "Historical claim supported": "Official retrospective and Tasks explanation",
      "Research packages": "3",
      "Authority": "Official project",
      "Durability": "DURABLE"
    },
    {
      "ID": "S163",
      "Date": "2026-03-16",
      "Source type": "BLOG",
      "Organization": "Model Context Protocol",
      "Title": "Tool Annotations as Risk Vocabulary: What Hints Can and Can't Do",
      "URL": "https://blog.modelcontextprotocol.io/posts/2026-03-16-tool-annotations/",
      "Version": "Current interpretation",
      "Claim supported": "Annotations are untrusted hints, not enforcement or prompt-injection defenses",
      "Historical claim supported": "Annotations are untrusted hints, not enforcement or prompt-injection defenses",
      "Research packages": "3",
      "Authority": "Official project",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S164",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "Model Context Protocol",
      "Title": "Extensions Overview",
      "URL": "https://modelcontextprotocol.io/extensions/overview",
      "Version": "Current",
      "Claim supported": "Extensions are separate from core protocol and version independently",
      "Historical claim supported": "Extensions are separate from core protocol and version independently",
      "Research packages": "3",
      "Authority": "Official project",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S165",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "EXTENSION",
      "Organization": "Model Context Protocol",
      "Title": "MCP Tasks Extension Overview",
      "URL": "https://tasks.extensions.modelcontextprotocol.io/",
      "Version": "Current extension",
      "Claim supported": "Tasks are a separately versioned extension in the 2026 architecture",
      "Historical claim supported": "Tasks are a separately versioned extension in the 2026 architecture",
      "Research packages": "3",
      "Authority": "Official project",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S166",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "SDK_DOCS",
      "Organization": "Model Context Protocol Python SDK",
      "Title": "Protocol Versions",
      "URL": "https://py.sdk.modelcontextprotocol.io/protocol-versions/",
      "Version": "SDK v2",
      "Claim supported": "Modern versus handshake-era compatibility model",
      "Historical claim supported": "Modern versus handshake-era compatibility model",
      "Research packages": "3",
      "Authority": "Official SDK",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S167",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "SDK_DOCS",
      "Organization": "Model Context Protocol Python SDK",
      "Title": "Client",
      "URL": "https://py.sdk.modelcontextprotocol.io/client/",
      "Version": "SDK v2",
      "Claim supported": "Local, remote and in-process client options Client connection forms: in-process, Streamable HTTP and stdio; client represents one server relationship.",
      "Historical claim supported": "Local, remote and in-process client options",
      "Research packages": "3,5",
      "Authority": "Official SDK",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S168",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "SDK_DOCS",
      "Organization": "Model Context Protocol TypeScript SDK",
      "Title": "Supporting protocol revision 2026-07-28",
      "URL": "https://ts.sdk.modelcontextprotocol.io/v2/migration/support-2026-07-28",
      "Version": "SDK v2",
      "Claim supported": "Per-era codecs and current auth migration details SDK implementation notes for discovery, identity and MRTR.",
      "Historical claim supported": "Per-era codecs and current auth migration details",
      "Research packages": "3,5",
      "Authority": "Official SDK",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S169",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "OpenAI",
      "Title": "Function calling",
      "URL": "https://developers.openai.com/api/docs/guides/function-calling",
      "Version": "Current",
      "Claim supported": "Current function definitions, tool loop, strict mode, tool choice and tool search",
      "Historical claim supported": "Current function definitions, tool loop, strict mode, tool choice and tool search",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S170",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "OpenAI",
      "Title": "MCP and Connectors",
      "URL": "https://developers.openai.com/api/docs/guides/tools-connectors-mcp",
      "Version": "Current",
      "Claim supported": "Remote MCP listing/calling, approvals and provider-hosted execution",
      "Historical claim supported": "Remote MCP listing/calling, approvals and provider-hosted execution",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S171",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "SDK_DOCS",
      "Organization": "OpenAI",
      "Title": "OpenAI Agents SDK — Tools",
      "URL": "https://openai.github.io/openai-agents-python/tools/",
      "Version": "Current",
      "Claim supported": "Function tools, hosted MCP tools, tool search, namespaces and execution options",
      "Historical claim supported": "Function tools, hosted MCP tools, tool search, namespaces and execution options",
      "Research packages": "3",
      "Authority": "Official SDK",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S172",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "OpenAI",
      "Title": "Structured model outputs",
      "URL": "https://developers.openai.com/api/docs/guides/structured-outputs",
      "Version": "Current",
      "Claim supported": "Distinction between constrained model output and external tool result structure",
      "Historical claim supported": "Distinction between constrained model output and external tool result structure",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S173",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "Anthropic",
      "Title": "Handle tool calls",
      "URL": "https://platform.claude.com/docs/en/agents-and-tools/tool-use/handle-tool-calls",
      "Version": "Current",
      "Claim supported": "Application tool execution and result-return loop",
      "Historical claim supported": "Application tool execution and result-return loop",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S174",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "Anthropic",
      "Title": "Tool search tool",
      "URL": "https://platform.claude.com/docs/en/agents-and-tools/tool-use/tool-search-tool",
      "Version": "Current",
      "Claim supported": "Deferred tool loading and large-catalog search",
      "Historical claim supported": "Deferred tool loading and large-catalog search",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S175",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "Anthropic",
      "Title": "MCP connector",
      "URL": "https://platform.claude.com/docs/en/agents-and-tools/mcp-connector",
      "Version": "Current",
      "Claim supported": "Messages API connection to remote MCP servers The beta Messages API connector uses tools from public HTTPS remote MCP servers over Streamable HTTP or legacy SSE.",
      "Historical claim supported": "Messages API connection to remote MCP servers",
      "Research packages": "3,5",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED",
      "Notes": "First-party product documentation rechecked and normalized on 2026-08-25; the package URL remains in the package source map."
    },
    {
      "ID": "S176",
      "Date": "2025-11-24",
      "Source type": "ENGINEERING",
      "Organization": "Anthropic",
      "Title": "Advanced tool use",
      "URL": "https://www.anthropic.com/engineering/advanced-tool-use",
      "Version": "Current-era analysis",
      "Claim supported": "Tool search and large-catalog context/selection concerns",
      "Historical claim supported": "Tool search and large-catalog context/selection concerns",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S177",
      "Date": "2026-07-30 (page update)",
      "Source type": "DOCS",
      "Organization": "Google",
      "Title": "Function calling with the Gemini API",
      "URL": "https://ai.google.dev/gemini-api/docs/function-calling",
      "Version": "Current",
      "Claim supported": "Gemini function declarations, developer execution, parallel/compositional calls and remote MCP",
      "Historical claim supported": "Gemini function declarations, developer execution, parallel/compositional calls and remote MCP",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S178",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "DOCS",
      "Organization": "Google",
      "Title": "Thought signatures",
      "URL": "https://ai.google.dev/gemini-api/docs/thought-signatures",
      "Version": "Current",
      "Claim supported": "Provider-specific continuity requirements around tool calls",
      "Historical claim supported": "Provider-specific continuity requirements around tool calls",
      "Research packages": "3",
      "Authority": "Primary vendor",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S179",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "STANDARD",
      "Organization": "OpenAPI Initiative",
      "Title": "What is OpenAPI?",
      "URL": "https://www.openapis.org/what-is-openapi",
      "Version": "Current",
      "Claim supported": "OpenAPI as a machine-readable HTTP API description",
      "Historical claim supported": "OpenAPI as a machine-readable HTTP API description",
      "Research packages": "3",
      "Authority": "Primary standard organization",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S180",
      "Date": "2026-08-25 (retrieved)",
      "Source type": "STANDARD",
      "Organization": "OpenAPI Initiative",
      "Title": "OpenAPI Specification",
      "URL": "https://spec.openapis.org/oas/",
      "Version": "Current index",
      "Claim supported": "Current OpenAPI versioned specifications",
      "Historical claim supported": "Current OpenAPI versioned specifications",
      "Research packages": "3",
      "Authority": "Primary standard organization",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S181",
      "Date": "2020-12",
      "Source type": "STANDARD",
      "Organization": "JSON Schema",
      "Title": "JSON Schema 2020-12",
      "URL": "https://json-schema.org/draft/2020-12",
      "Version": "2020-12",
      "Claim supported": "Schema dialect used as current MCP default",
      "Historical claim supported": "Schema dialect used as current MCP default",
      "Research packages": "3",
      "Authority": "Primary standard",
      "Durability": "DURABLE"
    },
    {
      "ID": "S182",
      "Date": "2026-03 (published)",
      "Source type": "SERP_COMPETITOR",
      "Organization": "MCP Institute",
      "Title": "MCP vs Direct Function Calling: When to Use Which",
      "URL": "https://mcp.institute/research/mcp-vs-function-calling",
      "Version": "Competitor snapshot",
      "Claim supported": "Current SERP framing and comparison gaps",
      "Historical claim supported": "Current SERP framing and comparison gaps",
      "Research packages": "3",
      "Authority": "Secondary discovery only",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S183",
      "Date": "2026-04 (published)",
      "Source type": "SERP_COMPETITOR",
      "Organization": "Goodcall",
      "Title": "MCP vs. Function Calling",
      "URL": "https://www.goodcall.com/voice-ai/mcp-vs-function-calling",
      "Version": "Competitor snapshot",
      "Claim supported": "Outdated HTTP+SSE framing in current results",
      "Historical claim supported": "Outdated HTTP+SSE framing in current results",
      "Research packages": "3",
      "Authority": "Secondary discovery only",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S184",
      "Date": "2025 (published)",
      "Source type": "SERP_COMPETITOR",
      "Organization": "AI Agents Kit",
      "Title": "MCP vs Function Calling: When to Use Each",
      "URL": "https://aiagentskit.com/blog/mcp-vs-function-calling/",
      "Version": "Competitor snapshot",
      "Claim supported": "Stateful-MCP comparison still appearing in results",
      "Historical claim supported": "Stateful-MCP comparison still appearing in results",
      "Research packages": "3",
      "Authority": "Secondary discovery only",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S185",
      "Date": "2026 (retrieved)",
      "Source type": "SERP_COMPETITOR",
      "Organization": "Tetrate",
      "Title": "MCP vs OpenAI Function Calling",
      "URL": "https://tetrate.io/learn/ai/mcp/mcp-vs-openai-function-calling",
      "Version": "Competitor snapshot",
      "Claim supported": "Persistent-session framing and search-intent coverage",
      "Historical claim supported": "Persistent-session framing and search-intent coverage",
      "Research packages": "3",
      "Authority": "Secondary discovery only",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S186",
      "Date": "2026 (published)",
      "Source type": "SERP_COMPETITOR",
      "Organization": "ClearPeaks",
      "Title": "Model Context Protocol vs. Function Calling: A Practical Comparison",
      "URL": "https://www.clearpeaks.com/model-context-protocol-vs-function-calling-a-practical-comparison-for-ai-agents/",
      "Version": "Competitor snapshot",
      "Claim supported": "Example benchmark methodology and limits",
      "Historical claim supported": "Example benchmark methodology and limits",
      "Research packages": "3",
      "Authority": "Secondary discovery only",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S187",
      "Date": "2025-11-25",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Authorization 2025-11-25",
      "URL": "https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization",
      "Version": "2025-11-25",
      "Claim supported": "Late-2025 authorization semantics and registration options",
      "Historical claim supported": "Late-2025 authorization semantics and registration options",
      "Research packages": "4",
      "Authority": "Authoritative specification",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S188",
      "Date": "2026-05-20",
      "Source type": "GOV_GUIDANCE",
      "Organization": "NSA Artificial Intelligence Security Center",
      "Title": "Model Context Protocol: Security Design Considerations for AI-Driven Automation",
      "URL": "https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf",
      "Version": "Predates 2026-07-28 GA",
      "Claim supported": "Government threat model and production recommendations; session-specific passages require version qualification",
      "Historical claim supported": "Government threat model and production recommendations; session-specific passages require version qualification",
      "Research packages": "4",
      "Authority": "Government primary source",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S189",
      "Date": "2026-05-20",
      "Source type": "PRESS_RELEASE",
      "Organization": "NSA",
      "Title": "NSA Releases Security Design Considerations for AI-Driven Automation Leveraging MCP",
      "URL": "https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496698/nsa-releases-security-design-considerations-for-ai-driven-automation-leveraging/",
      "Version": "Predates 2026-07-28 GA",
      "Claim supported": "Release date, adoption context and continuum-of-security framing",
      "Historical claim supported": "Release date, adoption context and continuum-of-security framing",
      "Research packages": "4",
      "Authority": "Government primary source",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S190",
      "Date": "2026",
      "Source type": "FRAMEWORK",
      "Organization": "OWASP Foundation",
      "Title": "OWASP MCP Top 10",
      "URL": "https://owasp.org/www-project-mcp-top-10/",
      "Version": "v0.1 beta",
      "Claim supported": "Community risk taxonomy; beta rather than final standard",
      "Historical claim supported": "Community risk taxonomy; beta rather than final standard",
      "Research packages": "4",
      "Authority": "Authoritative project source",
      "Notes": "",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S191",
      "Date": "2025-01",
      "Source type": "STANDARD",
      "Organization": "IETF",
      "Title": "Best Current Practice for OAuth 2.0 Security",
      "URL": "https://www.rfc-editor.org/rfc/rfc9700",
      "Version": "RFC 9700",
      "Claim supported": "OAuth security best current practice",
      "Historical claim supported": "OAuth security best current practice",
      "Research packages": "4",
      "Authority": "Formal standards source",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S192",
      "Date": "2022-03",
      "Source type": "STANDARD",
      "Organization": "IETF",
      "Title": "OAuth 2.0 Authorization Server Issuer Identification",
      "URL": "https://www.rfc-editor.org/rfc/rfc9207",
      "Version": "RFC 9207",
      "Claim supported": "Authorization-response issuer validation",
      "Historical claim supported": "Authorization-response issuer validation",
      "Research packages": "4",
      "Authority": "Formal standards source",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S193",
      "Date": "2012-10",
      "Source type": "STANDARD",
      "Organization": "IETF",
      "Title": "OAuth 2.0 Bearer Token Usage",
      "URL": "https://www.rfc-editor.org/rfc/rfc6750",
      "Version": "RFC 6750",
      "Claim supported": "Bearer-token transmission and challenge rules",
      "Historical claim supported": "Bearer-token transmission and challenge rules",
      "Research packages": "4",
      "Authority": "Formal standards source",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S194",
      "Date": "2015-07",
      "Source type": "STANDARD",
      "Organization": "IETF",
      "Title": "OAuth 2.0 Dynamic Client Registration Protocol",
      "URL": "https://www.rfc-editor.org/rfc/rfc7591",
      "Version": "RFC 7591",
      "Claim supported": "Historical DCR mechanism now deprecated by current MCP",
      "Historical claim supported": "Historical DCR mechanism now deprecated by current MCP",
      "Research packages": "4",
      "Authority": "Formal standards source",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S195",
      "Date": "2025-04-07",
      "Source type": "SECURITY_RESEARCH",
      "Organization": "Invariant Labs",
      "Title": "WhatsApp MCP Exploited: Exfiltrating Your Message History via MCP",
      "URL": "https://invariantlabs.ai/blog/whatsapp-mcp-exploited",
      "Version": "Session-era clients",
      "Claim supported": "Practical cross-server/rug-pull demonstration",
      "Historical claim supported": "Practical cross-server/rug-pull demonstration",
      "Research packages": "4",
      "Authority": "Original research",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S196",
      "Date": "2026-05-21",
      "Source type": "PREPRINT",
      "Organization": "Zhou et al.",
      "Title": "A First Measurement Study on Authentication Security in Real-World Remote MCP Servers",
      "URL": "https://arxiv.org/abs/2605.22333",
      "Version": "Servers measured before 2026-07-28",
      "Claim supported": "7,973 live servers, authentication distribution, 119-server OAuth subset and nine CVEs; preprint with selection limits",
      "Historical claim supported": "7,973 live servers, authentication distribution, 119-server OAuth subset and nine CVEs; preprint with selection limits",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "Do not generalize OAuth flaw rates beyond the testable subset.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S197",
      "Date": "2026-05-20",
      "Source type": "PREPRINT",
      "Organization": "VIPER-MCP authors",
      "Title": "VIPER-MCP: Detecting and Exploiting Taint-Style Vulnerabilities in MCP Servers",
      "URL": "https://arxiv.org/abs/2605.21392",
      "Version": "2025-2026 ecosystem",
      "Claim supported": "Large-scale repository audit; 106 confirmed findings and 67 CVEs as reported by authors",
      "Historical claim supported": "Large-scale repository audit; 106 confirmed findings and 67 CVEs as reported by authors",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "Preprint statistics require method and version qualification.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S198",
      "Date": "2026-03-23",
      "Source type": "PEER_REVIEW/PREPRINT",
      "Organization": "Huang et al.",
      "Title": "Model Context Protocol Threat Modeling and Analysis of Vulnerabilities to Prompt Injection with Tool Poisoning",
      "URL": "https://doi.org/10.3390/jcp6030084",
      "Version": "Clients tested in 2025/2026",
      "Claim supported": "STRIDE/DREAD model and seven-client tool-poisoning evaluation",
      "Historical claim supported": "STRIDE/DREAD model and seven-client tool-poisoning evaluation",
      "Research packages": "4",
      "Authority": "Peer-reviewed research",
      "Notes": "",
      "Durability": "DURABLE"
    },
    {
      "ID": "S199",
      "Date": "2026-03-18",
      "Source type": "PREPRINT",
      "Organization": "Shen, Toyoda and Leung",
      "Title": "MCP-38: A Comprehensive Threat Taxonomy for MCP Systems",
      "URL": "https://arxiv.org/abs/2603.18063",
      "Version": "2026 taxonomy",
      "Claim supported": "38-category MCP threat taxonomy",
      "Historical claim supported": "38-category MCP threat taxonomy",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S200",
      "Date": "2025-12-06",
      "Source type": "PREPRINT",
      "Organization": "Jamshidi et al.",
      "Title": "Securing the Model Context Protocol: Defending LLMs Against Tool Poisoning and Adversarial Attacks",
      "URL": "https://arxiv.org/abs/2512.06556",
      "Version": "2025 clients/models",
      "Claim supported": "Tool poisoning, shadowing, rug pulls and layered defense evaluation",
      "Historical claim supported": "Tool poisoning, shadowing, rug pulls and layered defense evaluation",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S201",
      "Date": "2026-01-12",
      "Source type": "PREPRINT",
      "Organization": "Li et al.",
      "Title": "MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP",
      "URL": "https://arxiv.org/abs/2601.07395",
      "Version": "2026 benchmark",
      "Claim supported": "Implicit tool poisoning and adaptive attack study",
      "Historical claim supported": "Implicit tool poisoning and adaptive attack study",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S202",
      "Date": "2026-06-25",
      "Source type": "PREPRINT",
      "Organization": "Liu et al.",
      "Title": "ShareLock: A Stealthy Multi-Tool Threshold Poisoning Attack Against MCP",
      "URL": "https://arxiv.org/abs/2606.27027",
      "Version": "2026 clients",
      "Claim supported": "Multi-tool threshold poisoning research",
      "Historical claim supported": "Multi-tool threshold poisoning research",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S203",
      "Date": "2026-04-18",
      "Source type": "PREPRINT",
      "Organization": "Turgut and Gümüş",
      "Title": "CASCADE: A Cascaded Hybrid Defense Architecture for Prompt Injection Detection in MCP-Based Systems",
      "URL": "https://arxiv.org/abs/2604.17125",
      "Version": "2026 defense study",
      "Claim supported": "Prompt-injection detector evaluation and limitations",
      "Historical claim supported": "Prompt-injection detector evaluation and limitations",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S204",
      "Date": "2026-08-01",
      "Source type": "PREPRINT",
      "Organization": "Corvus study author",
      "Title": "Exposed by Design: A Dynamic Security Assessment of Internet-Facing MCP Servers at Scale",
      "URL": "https://arxiv.org/abs/2608.00150",
      "Version": "July 2026 scans",
      "Claim supported": "Dynamic audit of internet-facing servers; reported exposure and churn figures",
      "Historical claim supported": "Dynamic audit of internet-facing servers; reported exposure and churn figures",
      "Research packages": "4",
      "Authority": "Primary research preprint",
      "Notes": "Very recent preprint; preserve methodology caveats.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S205",
      "Date": "2025-07-04",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Python SDK",
      "Title": "CVE-2025-53366: Validation error amplification / denial of service",
      "URL": "https://github.com/advisories/GHSA-3qhf-m339-9g5v",
      "Version": "<1.9.4",
      "Claim supported": "Validation error amplification / denial of service; patched/fixed status: 1.9.4",
      "Historical claim supported": "Validation error amplification / denial of service; patched/fixed status: 1.9.4",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S206",
      "Date": "2025-07-04",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Python SDK",
      "Title": "CVE-2025-53365: Closed-resource handling denial of service",
      "URL": "https://github.com/advisories/GHSA-j975-95f5-7wqh",
      "Version": "<1.10.0",
      "Claim supported": "Closed-resource handling denial of service; patched/fixed status: 1.10.0",
      "Historical claim supported": "Closed-resource handling denial of service; patched/fixed status: 1.10.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S207",
      "Date": "2026-02-20",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Go SDK",
      "Title": "CVE-2026-34742: DNS rebinding protection gap for localhost HTTP servers",
      "URL": "https://github.com/advisories/GHSA-xw59-hvm2-8pj6",
      "Version": "<1.4.0",
      "Claim supported": "DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.4.0",
      "Historical claim supported": "DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.4.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S208",
      "Date": "2026-02-26",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Java SDK",
      "Title": "CVE-2026-35568: DNS rebinding protection gap for localhost HTTP servers",
      "URL": "https://github.com/advisories/GHSA-8jxr-pr72-r468",
      "Version": "<1.0.0",
      "Claim supported": "DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.0.0",
      "Historical claim supported": "DNS rebinding protection gap for localhost HTTP servers; patched/fixed status: 1.0.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S209",
      "Date": "2026-04-14",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Rust SDK",
      "Title": "CVE-2026-42559: DNS rebinding protection gap",
      "URL": "https://github.com/advisories/GHSA-89vp-x53w-74fx",
      "Version": "<1.4.0",
      "Claim supported": "DNS rebinding protection gap; patched/fixed status: 1.4.0",
      "Historical claim supported": "DNS rebinding protection gap; patched/fixed status: 1.4.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S210",
      "Date": "2026-06-08",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Ruby SDK",
      "Title": "CVE-2026-63118: DNS rebinding protection gap",
      "URL": "https://github.com/advisories/GHSA-rjr6-rcgv-9m7m",
      "Version": "<=0.22.0",
      "Claim supported": "DNS rebinding protection gap; patched/fixed status: 0.23.0",
      "Historical claim supported": "DNS rebinding protection gap; patched/fixed status: 0.23.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S211",
      "Date": "2026-06-24",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Ruby SDK",
      "Title": "CVE-2026-67431: Protocol-session poisoning / state confusion in legacy session architecture",
      "URL": "https://github.com/advisories/GHSA-5p9g-j988-pcwv",
      "Version": "<=0.22.0",
      "Claim supported": "Protocol-session poisoning / state confusion in legacy session architecture; patched/fixed status: 0.23.0",
      "Historical claim supported": "Protocol-session poisoning / state confusion in legacy session architecture; patched/fixed status: 0.23.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/session. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S212",
      "Date": "2026-06-24",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Ruby SDK",
      "Title": "CVE-2026-67430: Unbounded stdio message handling can exhaust resources",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2026-67430",
      "Version": "LIVE-CHECK REQUIRED",
      "Claim supported": "Unbounded stdio message handling can exhaust resources; patched/fixed status: 0.23.0 reported",
      "Historical claim supported": "Unbounded stdio message handling can exhaust resources; patched/fixed status: 0.23.0 reported",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/stdio. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S213",
      "Date": "2026-06-24",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP Ruby SDK",
      "Title": "CVE-2026-67432: Legacy session retention / cleanup flaw",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2026-67432",
      "Version": "LIVE-CHECK REQUIRED",
      "Claim supported": "Legacy session retention / cleanup flaw; patched/fixed status: 0.23.0 reported",
      "Historical claim supported": "Legacy session retention / cleanup flaw; patched/fixed status: 0.23.0 reported",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/session. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S214",
      "Date": "2026-01-08",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP TypeScript SDK",
      "Title": "CVE-2026-0621: UriTemplate regular-expression denial of service",
      "URL": "https://github.com/advisories/GHSA-cqwc-fm46-7fff",
      "Version": "<1.25.2",
      "Claim supported": "UriTemplate regular-expression denial of service; patched/fixed status: 1.25.2",
      "Historical claim supported": "UriTemplate regular-expression denial of service; patched/fixed status: 1.25.2",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: SDK/parser. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S215",
      "Date": "2025-10-16",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCP reference Git server",
      "Title": "CVE-2025-68143: Repository path validation weakness",
      "URL": "https://github.com/advisories/GHSA-5cgr-j3jf-jw3v",
      "Version": "<2025.9.25",
      "Claim supported": "Repository path validation weakness; patched/fixed status: 2025.9.25 / server removed",
      "Historical claim supported": "Repository path validation weakness; patched/fixed status: 2025.9.25 / server removed",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server implementation. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S216",
      "Date": "2026-04-29",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Official MCP Registry",
      "Title": "CVE-2026-44430: Server-side request forgery in registry processing",
      "URL": "https://github.com/advisories/GHSA-r48c-v28r-pf6v",
      "Version": "<1.7.7",
      "Claim supported": "Server-side request forgery in registry processing; patched/fixed status: 1.7.7",
      "Historical claim supported": "Server-side request forgery in registry processing; patched/fixed status: 1.7.7",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Registry. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S217",
      "Date": "2026-04-29",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Official MCP Registry",
      "Title": "CVE-2026-44428: OIDC token replay / validation flaw",
      "URL": "https://github.com/advisories/GHSA-95c3-6vvw-4mrq",
      "Version": "<1.7.6",
      "Claim supported": "OIDC token replay / validation flaw; patched/fixed status: 1.7.6",
      "Historical claim supported": "OIDC token replay / validation flaw; patched/fixed status: 1.7.6",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Registry/auth. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S218",
      "Date": "2026-04-29",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Official MCP Registry",
      "Title": "CVE-2026-44427: Open redirect",
      "URL": "https://github.com/advisories/GHSA-v8vw-gw5j-w7m6",
      "Version": ">=1.1.0,<1.7.5",
      "Claim supported": "Open redirect; patched/fixed status: 1.7.5",
      "Historical claim supported": "Open redirect; patched/fixed status: 1.7.5",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Registry/web. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S219",
      "Date": "2026-05-01",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Official MCP Registry",
      "Title": "GHSA-rqv2-m695-f8j4: Stored cross-site scripting",
      "URL": "https://github.com/advisories/GHSA-rqv2-m695-f8j4",
      "Version": "LIVE-CHECK REQUIRED",
      "Claim supported": "Stored cross-site scripting; patched/fixed status: LIVE-CHECK REQUIRED",
      "Historical claim supported": "Stored cross-site scripting; patched/fixed status: LIVE-CHECK REQUIRED",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Registry/web. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S220",
      "Date": "2026-05-01",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Official MCP Registry",
      "Title": "GHSA-2v5f-5r6w-p67r: OCI verification fail-open behavior",
      "URL": "https://github.com/advisories/GHSA-2v5f-5r6w-p67r",
      "Version": "<1.7.9",
      "Claim supported": "OCI verification fail-open behavior; patched/fixed status: 1.7.9",
      "Historical claim supported": "OCI verification fail-open behavior; patched/fixed status: 1.7.9",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Registry/supply chain. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S221",
      "Date": "2025-08-29",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Microsoft Playwright MCP",
      "Title": "CVE-2025-9611: DNS rebinding against localhost HTTP mode",
      "URL": "https://github.com/advisories/GHSA-6fg3-hvw7-2fwq",
      "Version": "<0.0.40",
      "Claim supported": "DNS rebinding against localhost HTTP mode; patched/fixed status: 0.0.40",
      "Historical claim supported": "DNS rebinding against localhost HTTP mode; patched/fixed status: 0.0.40",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S222",
      "Date": "2026-08-07",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Google MCP Toolbox for Databases",
      "Title": "CVE-2026-9739: DNS rebinding in legacy SSE/local deployment",
      "URL": "https://github.com/advisories/GHSA-7pf3-8xx7-rvhf",
      "Version": "<1.2.0",
      "Claim supported": "DNS rebinding in legacy SSE/local deployment; patched/fixed status: 1.2.0",
      "Historical claim supported": "DNS rebinding in legacy SSE/local deployment; patched/fixed status: 1.2.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S223",
      "Date": "2026-03-03",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "CircleCI MCP Server",
      "Title": "GHSA-jwj7-74jh-p5c4: DNS rebinding protection weakness",
      "URL": "https://github.com/advisories/GHSA-jwj7-74jh-p5c4",
      "Version": "<0.17.0",
      "Claim supported": "DNS rebinding protection weakness; patched/fixed status: 0.17.0",
      "Historical claim supported": "DNS rebinding protection weakness; patched/fixed status: 0.17.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/transport. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S224",
      "Date": "2026-01-16",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MCPJam Inspector",
      "Title": "CVE-2026-23744: Remote command execution",
      "URL": "https://github.com/advisories/GHSA-232v-j27c-5pp6",
      "Version": "<=1.4.2",
      "Claim supported": "Remote command execution; patched/fixed status: 1.4.3",
      "Historical claim supported": "Remote command execution; patched/fixed status: 1.4.3",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/developer tool. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S225",
      "Date": "2026-04-03",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "FastMCP",
      "Title": "CVE-2026-27124: OAuth proxy callback missing consent binding; confused deputy",
      "URL": "https://github.com/advisories/GHSA-rww4-4w9c-7733",
      "Version": "<3.2.0",
      "Claim supported": "OAuth proxy callback missing consent binding; confused deputy; patched/fixed status: 3.2.0",
      "Historical claim supported": "OAuth proxy callback missing consent binding; confused deputy; patched/fixed status: 3.2.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Framework/auth. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S226",
      "Date": "2026-05-20",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "mcp-pinot",
      "Title": "CVE-2026-49257: Network service bound broadly without authentication",
      "URL": "https://github.com/advisories/GHSA-73cv-556c-w3g6",
      "Version": "<=3.0.1",
      "Claim supported": "Network service bound broadly without authentication; patched/fixed status: 3.1.0",
      "Historical claim supported": "Network service bound broadly without authentication; patched/fixed status: 3.1.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/deployment. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S227",
      "Date": "2026-04-20",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "GitHub MCP Server",
      "Title": "CVE-2026-47427: Nil-pointer denial of service",
      "URL": "https://github.com/advisories/GHSA-w4q6-qw23-4rg7",
      "Version": "<1.1.0",
      "Claim supported": "Nil-pointer denial of service; patched/fixed status: 1.1.0",
      "Historical claim supported": "Nil-pointer denial of service; patched/fixed status: 1.1.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server implementation. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S228",
      "Date": "2026-05-16",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "GitHub MCP Server",
      "Title": "CVE-2026-48529: Lockdown mode cross-user authorization separation flaw",
      "URL": "https://github.com/advisories/GHSA-pjp5-fpmr-3349",
      "Version": ">=0.22.0,<1.1.2",
      "Claim supported": "Lockdown mode cross-user authorization separation flaw; patched/fixed status: 1.1.2",
      "Historical claim supported": "Lockdown mode cross-user authorization separation flaw; patched/fixed status: 1.1.2",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/authorization. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S229",
      "Date": "2026-05-04",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Kubernetes MCP Server",
      "Title": "CVE-2026-46519: Presentation-only authorization without server-side enforcement",
      "URL": "https://github.com/advisories/GHSA-cr22-wjx7-2w6m",
      "Version": "<3.6.0",
      "Claim supported": "Presentation-only authorization without server-side enforcement; patched/fixed status: 3.6.0",
      "Historical claim supported": "Presentation-only authorization without server-side enforcement; patched/fixed status: 3.6.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/authorization. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S230",
      "Date": "2026-05-29",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "flyto-core",
      "Title": "CVE-2026-55786: Unauthenticated command execution through MCP capability",
      "URL": "https://github.com/advisories/GHSA-h9f9-h6gm-wc85",
      "Version": ">=2.26.2,<2.26.4",
      "Claim supported": "Unauthenticated command execution through MCP capability; patched/fixed status: 2.26.4",
      "Historical claim supported": "Unauthenticated command execution through MCP capability; patched/fixed status: 2.26.4",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server implementation. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S231",
      "Date": "2026-01-15",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "MySQL MCP Server",
      "Title": "CVE-2026-11529: SQL injection through insufficient input handling",
      "URL": "https://github.com/advisories/GHSA-mvq4-39wx-6h5g",
      "Version": "<0.3.0",
      "Claim supported": "SQL injection through insufficient input handling; patched/fixed status: 0.3.0",
      "Historical claim supported": "SQL injection through insufficient input handling; patched/fixed status: 0.3.0",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server implementation. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S232",
      "Date": "2026-05-22",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "aws-mcp",
      "Title": "CVE-2026-5059: Command injection",
      "URL": "https://github.com/advisories/GHSA-fgmx-xfp3-w28p",
      "Version": "<=1.7.0",
      "Claim supported": "Command injection; patched/fixed status: No patch listed when recorded",
      "Historical claim supported": "Command injection; patched/fixed status: No patch listed when recorded",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server implementation. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S233",
      "Date": "2026-05-09",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Claude Code Action",
      "Title": "CVE-2026-47751: Malicious repository .mcp.json can execute configured server code",
      "URL": "https://github.com/advisories/GHSA-8q5r-mmjf-575q",
      "Version": "<1.0.74",
      "Claim supported": "Malicious repository .mcp.json can execute configured server code; patched/fixed status: 1.0.74",
      "Historical claim supported": "Malicious repository .mcp.json can execute configured server code; patched/fixed status: 1.0.74",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/project config. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S234",
      "Date": "2026-05-25",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Apify MCP Server",
      "Title": "CVE-2026-50143: Path/token authorization weakness",
      "URL": "https://github.com/advisories/GHSA-6gr2-qh89-hxwm",
      "Version": "<0.10.11",
      "Claim supported": "Path/token authorization weakness; patched/fixed status: 0.10.11",
      "Historical claim supported": "Path/token authorization weakness; patched/fixed status: 0.10.11",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/authorization. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S235",
      "Date": "2026-03-24",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "LibreChat",
      "Title": "CVE-2026-31944: OAuth callback binding/account-linking weakness",
      "URL": "https://github.com/advisories/GHSA-vf7j-7mrx-hp7g",
      "Version": "LIVE-CHECK REQUIRED",
      "Claim supported": "OAuth callback binding/account-linking weakness; patched/fixed status: 0.8.3-rc1 reported",
      "Historical claim supported": "OAuth callback binding/account-linking weakness; patched/fixed status: 0.8.3-rc1 reported",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/auth. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S236",
      "Date": "2026-03-26",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "LibreChat",
      "Title": "CVE-2026-32625: Environment-expanded MCP URL can expose secrets",
      "URL": "https://github.com/advisories/GHSA-4pcc-j6m6-wcwx",
      "Version": "<=0.8.3",
      "Claim supported": "Environment-expanded MCP URL can expose secrets; patched/fixed status: 0.8.4-rc1 reported",
      "Historical claim supported": "Environment-expanded MCP URL can expose secrets; patched/fixed status: 0.8.4-rc1 reported",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/configuration. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S237",
      "Date": "2026-03-26",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "LibreChat",
      "Title": "GHSA-pmw7-gqwj-f954: Attacker-controlled headers can expose tokens",
      "URL": "https://github.com/advisories/GHSA-pmw7-gqwj-f954",
      "Version": ">=0.8.2-rc1,<=0.8.3-rc1",
      "Claim supported": "Attacker-controlled headers can expose tokens; patched/fixed status: >=0.8.3-rc2",
      "Historical claim supported": "Attacker-controlled headers can expose tokens; patched/fixed status: >=0.8.3-rc2",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/auth. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S238",
      "Date": "2026-04-01",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "PraisonAI",
      "Title": "CVE-2026-40159: Environment variables inherited by local MCP processes",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2026-40159",
      "Version": "<4.5.128",
      "Claim supported": "Environment variables inherited by local MCP processes; patched/fixed status: 4.5.128",
      "Historical claim supported": "Environment variables inherited by local MCP processes; patched/fixed status: 4.5.128",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/local process. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S239",
      "Date": "2026-04-10",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "PraisonAI",
      "Title": "CVE-2026-41497: Unsafe command parsing for MCP server configuration",
      "URL": "https://github.com/advisories/GHSA-9qhq-v63v-fv3j",
      "Version": "<=4.5.148",
      "Claim supported": "Unsafe command parsing for MCP server configuration; patched/fixed status: Patched after 4.5.148",
      "Historical claim supported": "Unsafe command parsing for MCP server configuration; patched/fixed status: Patched after 4.5.148",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/local process. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S240",
      "Date": "2026-06-01",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "PraisonAI",
      "Title": "CVE-2026-57124: Unauthenticated remote MCP connect path",
      "URL": "https://github.com/advisories/GHSA-p75f-6fp4-p57w",
      "Version": "<=4.6.48",
      "Claim supported": "Unauthenticated remote MCP connect path; patched/fixed status: 4.6.59",
      "Historical claim supported": "Unauthenticated remote MCP connect path; patched/fixed status: 4.6.59",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/network. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S241",
      "Date": "2026-05-12",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "PraisonAI",
      "Title": "CVE-2026-47394: Arbitrary local file read through MCP integration",
      "URL": "https://github.com/advisories/GHSA-9cr9-25q5-8prj",
      "Version": "<=4.6.39",
      "Claim supported": "Arbitrary local file read through MCP integration; patched/fixed status: 4.6.40",
      "Historical claim supported": "Arbitrary local file read through MCP integration; patched/fixed status: 4.6.40",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/server. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S242",
      "Date": "2026-03-15",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Nginx UI MCP integration",
      "Title": "CVE-2026-33032: Unauthenticated MCP endpoint enabling administrative takeover",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2026-33032",
      "Version": "<=2.3.3 reported",
      "Claim supported": "Unauthenticated MCP endpoint enabling administrative takeover; patched/fixed status: 2.3.4 reported",
      "Historical claim supported": "Unauthenticated MCP endpoint enabling administrative takeover; patched/fixed status: 2.3.4 reported",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Server/product integration. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S243",
      "Date": "2025-07-09",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "mcp-remote",
      "Title": "CVE-2025-6514: Command injection in remote-server launcher",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2025-6514",
      "Version": "LIVE-CHECK REQUIRED",
      "Claim supported": "Command injection in remote-server launcher; patched/fixed status: LIVE-CHECK REQUIRED",
      "Historical claim supported": "Command injection in remote-server launcher; patched/fixed status: LIVE-CHECK REQUIRED",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Launcher/supply chain. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S244",
      "Date": "2026-01-23",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Postmark MCP impersonator",
      "Title": "MALICIOUS-PACKAGE: Malicious npm package impersonating an official server and exfiltrating API keys",
      "URL": "https://snyk.io/blog/postmark-mcp-server-backdoor/",
      "Version": ">=1.0.16 malicious series",
      "Claim supported": "Malicious npm package impersonating an official server and exfiltrating API keys; patched/fixed status: Remove package; use verified vendor source",
      "Historical claim supported": "Malicious npm package impersonating an official server and exfiltrating API keys; patched/fixed status: Remove package; use verified vendor source",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Supply chain. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S245",
      "Date": "2025-09-17",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Cursor",
      "Title": "CVE-2025-64109: Malicious project MCP configuration can trigger code execution",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2025-64109",
      "Version": "Before 2025.09.17-25b418f",
      "Claim supported": "Malicious project MCP configuration can trigger code execution; patched/fixed status: 2025.09.17-25b418f",
      "Historical claim supported": "Malicious project MCP configuration can trigger code execution; patched/fixed status: 2025.09.17-25b418f",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/project config. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S246",
      "Date": "2025-12-19",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "Zed",
      "Title": "CVE-2025-68433: Malicious project MCP configuration can trigger code execution",
      "URL": "https://nvd.nist.gov/vuln/detail/CVE-2025-68433",
      "Version": "<0.218.2-pre",
      "Claim supported": "Malicious project MCP configuration can trigger code execution; patched/fixed status: 0.218.2-pre",
      "Historical claim supported": "Malicious project MCP configuration can trigger code execution; patched/fixed status: 0.218.2-pre",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/project config. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S247",
      "Date": "2026-04-22",
      "Source type": "SECURITY_ADVISORY",
      "Organization": "OpenClaw",
      "Title": "CVE-2026-44118: Owner identity spoofing in MCP-connected workflow",
      "URL": "https://github.com/advisories/GHSA-r6xh-pqhr-v4xh",
      "Version": "<=2026.4.21",
      "Claim supported": "Owner identity spoofing in MCP-connected workflow; patched/fixed status: 2026.4.22",
      "Historical claim supported": "Owner identity spoofing in MCP-connected workflow; patched/fixed status: 2026.4.22",
      "Research packages": "4",
      "Authority": "Vendor advisory / CVE",
      "Notes": "Layer: Host/identity. Verify current affected and fixed ranges before publication.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S248",
      "Date": "2026",
      "Source type": "SECURITY_POLICY",
      "Organization": "Model Context Protocol",
      "Title": "Project Security Policy",
      "URL": "https://github.com/modelcontextprotocol/modelcontextprotocol/security/policy",
      "Version": "Current",
      "Claim supported": "Vulnerability reporting and scope",
      "Historical claim supported": "Vulnerability reporting and scope",
      "Research packages": "4",
      "Authority": "Official repository",
      "Notes": "",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S249",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Specification Overview — MCP 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/index",
      "Version": "2024-11-05",
      "Claim supported": "Launch-era host, client and server roles and stateful capability-negotiated architecture.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "DURABLE"
    },
    {
      "ID": "S250",
      "Date": "2024-11-05",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Base Protocol — MCP 2024-11-05",
      "URL": "https://modelcontextprotocol.io/specification/2024-11-05/basic",
      "Version": "2024-11-05",
      "Claim supported": "Launch-era protocol layering and absence of the later core authorization framework.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "DURABLE"
    },
    {
      "ID": "S251",
      "Date": "2025-06-18",
      "Source type": "SPEC",
      "Organization": "Model Context Protocol",
      "Title": "Architecture — MCP 2025-06-18",
      "URL": "https://modelcontextprotocol.io/specification/2025-06-18/architecture",
      "Version": "2025-06-18",
      "Claim supported": "Legacy architecture: host manages clients; each client maintains a stateful session with one server; isolation principles.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "DURABLE"
    },
    {
      "ID": "S252",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "TypeScript SDK v2 Documentation",
      "URL": "https://ts.sdk.modelcontextprotocol.io/v2/",
      "Version": "2026-07-28",
      "Claim supported": "Official TypeScript SDK v2 support for current MCP and examples of hosts connecting to servers.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S253",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "TypeScript SDK Protocol Versions",
      "URL": "https://ts.sdk.modelcontextprotocol.io/v2/protocol-versions",
      "Version": "2026-07-28",
      "Claim supported": "Modern versus legacy protocol eras and automatic compatibility behavior.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S254",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "Ruby SDK Client Lifecycle",
      "URL": "https://ruby.sdk.modelcontextprotocol.io/client/lifecycle/",
      "Version": "2026-07-28",
      "Claim supported": "Official SDK handling of both legacy and current protocol eras.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S255",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "PHP SDK Client Connections",
      "URL": "https://php.sdk.modelcontextprotocol.io/client/connecting/",
      "Version": "2026-07-28",
      "Claim supported": "Current connection behavior without an initialization handshake.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S256",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "Java SDK Client Documentation",
      "URL": "https://java.sdk.modelcontextprotocol.io/latest/client/",
      "Version": "Current",
      "Claim supported": "Official Java client implementation responsibilities and transports.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S257",
      "Date": "2026-07-28",
      "Source type": "SDK_DOC",
      "Organization": "Model Context Protocol",
      "Title": "Java SDK Server Documentation",
      "URL": "https://java.sdk.modelcontextprotocol.io/latest/server/",
      "Version": "Current",
      "Claim supported": "Official Java server implementation responsibilities and capabilities.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S258",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "Anthropic",
      "Title": "When to use desktop and web connectors",
      "URL": "https://support.claude.com/en/articles/11725091-when-to-use-desktop-and-web-connectors",
      "Version": "Current product state",
      "Claim supported": "Anthropic distinguishes local desktop extensions from cloud-brokered remote connectors across supported Claude surfaces.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S259",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "Anthropic",
      "Title": "Connect Claude Code to tools via MCP",
      "URL": "https://code.claude.com/docs/en/mcp",
      "Version": "Current product state",
      "Claim supported": "Claude Code as an MCP host/client and optional MCP server through claude mcp serve.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S260",
      "Date": "2026-06-30",
      "Source type": "VENDOR_DOC",
      "Organization": "Anthropic",
      "Title": "Getting started with local MCP servers on Claude Desktop",
      "URL": "https://support.claude.com/en/articles/10949351-getting-started-with-local-mcp-servers-on-claude-desktop",
      "Version": "Current product state",
      "Claim supported": "Claude Desktop local server configuration and management.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S261",
      "Date": "2026-08-25",
      "Source type": "DOCS",
      "Organization": "OpenAI",
      "Title": "Secure MCP Tunnel",
      "URL": "https://developers.openai.com/api/docs/guides/secure-mcp-tunnels",
      "Version": "Live documentation checked 2026-08-25",
      "Claim supported": "Supported private, on-premises, and developer-machine MCP servers can be exposed to ChatGPT through Secure MCP Tunnel.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze for package 5",
      "Authority": "Primary or first-party source",
      "Notes": "Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S262",
      "Date": "2025-06-04",
      "Source type": "VENDOR_RELEASE",
      "Organization": "OpenAI",
      "Title": "ChatGPT — Release Notes",
      "URL": "https://help.openai.com/en/articles/6825453-chatgpt-release-notes",
      "Version": "Historical adoption",
      "Claim supported": "Initial ChatGPT custom connector support through remote MCP.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S263",
      "Date": "2025-03-01",
      "Source type": "VENDOR_RELEASE",
      "Organization": "Microsoft",
      "Title": "Visual Studio Code 1.99 Release Notes",
      "URL": "https://code.visualstudio.com/updates/v1_99",
      "Version": "Historical adoption",
      "Claim supported": "Initial VS Code MCP support in agent mode.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S264",
      "Date": "2026-05-15",
      "Source type": "VENDOR_BLOG",
      "Organization": "Microsoft",
      "Title": "The Coding Harness Behind GitHub Copilot in VS Code",
      "URL": "https://code.visualstudio.com/blogs/2026/05/15/agent-harnesses-github-copilot-vscode",
      "Version": "Current architecture context",
      "Claim supported": "Agent harness responsibilities: context, model loop, tool calls and execution coordination.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S265",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "GitHub",
      "Title": "Extending GitHub Copilot cloud agent with MCP",
      "URL": "https://docs.github.com/en/copilot/concepts/agents/cloud-agent/mcp-and-cloud-agent",
      "Version": "Current product state",
      "Claim supported": "GitHub Copilot cloud agent can use tools from configured MCP servers, subject to its documented capability, authentication, and approval limitations.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S266",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "GitHub",
      "Title": "Configuring MCP servers for GitHub Copilot cloud agent",
      "URL": "https://docs.github.com/en/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers",
      "Version": "Current product state",
      "Claim supported": "GitHub documents how to configure MCP servers for GitHub Copilot cloud agent.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S267",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "GitHub",
      "Title": "Use the GitHub MCP Server from Copilot Chat",
      "URL": "https://docs.github.com/en/copilot/how-tos/copilot-on-github/copilot-for-github-tasks/using-the-github-mcp-server-from-copilot-chat",
      "Version": "Current product state",
      "Claim supported": "Copilot Chat host/client behavior with a preconfigured GitHub MCP server and user approval.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S268",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "GitHub",
      "Title": "Adding MCP servers for GitHub Copilot CLI",
      "URL": "https://docs.github.com/en/copilot/how-tos/copilot-cli/customize-copilot/add-mcp-servers",
      "Version": "Current product state",
      "Claim supported": "Copilot CLI local and remote MCP server support.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S269",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "Cursor",
      "Title": "Model Context Protocol (MCP)",
      "URL": "https://cursor.com/docs/mcp",
      "Version": "Current product state",
      "Claim supported": "Cursor as a host/client connecting to external MCP tools and data.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S270",
      "Date": "2026-08-25",
      "Source type": "DOCS",
      "Organization": "Microsoft",
      "Title": "Agent Host",
      "URL": "https://code.visualstudio.com/docs/agents/concepts/agent-host",
      "Version": "Live documentation checked 2026-08-25",
      "Claim supported": "Microsoft Agent Host is a distinct AHP runtime or process and should not be confused with the MCP host role.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze for package 5",
      "Authority": "Primary or first-party source",
      "Notes": "Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S271",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "Google",
      "Title": "Getting Started with Google MCP Servers",
      "URL": "https://codelabs.developers.google.com/getting-started-google-mcp-servers",
      "Version": "Current product state",
      "Claim supported": "Gemini CLI registration and use of Google-hosted MCP servers.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S272",
      "Date": "2025-12-17",
      "Source type": "VENDOR_BLOG",
      "Organization": "Zed Industries",
      "Title": "Zed Moves Toward Secure-by-Default: Introducing Worktree Trust",
      "URL": "https://zed.dev/blog/secure-by-default",
      "Version": "Current product/security state",
      "Claim supported": "Zed host behavior around project trust and automatic MCP server execution.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S273",
      "Date": "2026-08-25",
      "Source type": "VENDOR_DOC",
      "Organization": "Zed Industries",
      "Title": "Tool Permissions in Zed",
      "URL": "https://zed.dev/docs/ai/tool-permissions",
      "Version": "Current product state",
      "Claim supported": "Host-level MCP tool allow, deny and confirm policy.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S274",
      "Date": "2026-08-14",
      "Source type": "VENDOR_DOC",
      "Organization": "JetBrains",
      "Title": "Model Context Protocol in JetBrains AI Assistant",
      "URL": "https://www.jetbrains.com/help/ai-assistant/mcp.html",
      "Version": "AI Assistant 2026.2",
      "Claim supported": "JetBrains AI Assistant as MCP host/client; stdio, Streamable HTTP and legacy SSE support.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S275",
      "Date": "2026-05-13",
      "Source type": "VENDOR_DOC",
      "Organization": "JetBrains",
      "Title": "MCP Server",
      "URL": "https://www.jetbrains.com/help/pycharm/mcp-server.html",
      "Version": "PyCharm 2026.2",
      "Claim supported": "JetBrains IDEs as MCP servers exposing IDE tools to external clients.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S276",
      "Date": "2026-02-01",
      "Source type": "VENDOR_KB",
      "Organization": "JetBrains",
      "Title": "How JetBrains MCP Client and Server Options Differ",
      "URL": "https://youtrack.jetbrains.com/articles/SUPPORT-A-2455/What-MCP-options-do-JetBrains-IDE-and-AI-Assistant-offer-and-how-do-they-differ",
      "Version": "Current product state",
      "Claim supported": "Explicit distinction between JetBrains AI Assistant as client and the IDE as server.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S277",
      "Date": "2026-08-03",
      "Source type": "VENDOR_DOC",
      "Organization": "JetBrains",
      "Title": "Agents",
      "URL": "https://www.jetbrains.com/help/ai-assistant/agents.html",
      "Version": "AI Assistant 2026.2",
      "Claim supported": "JetBrains host can pass configured MCP tools to several agent implementations.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package; first-party product documentation rechecked and corrected on 2026-08-25.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S278",
      "Date": "2026-08-25",
      "Source type": "COMPETITOR",
      "Organization": "Tricentis",
      "Title": "MCP Server vs Client",
      "URL": "https://www.tricentis.com/learn/mcp-server-vs-client",
      "Version": "Search-result audit",
      "Claim supported": "Competitor page retaining initialize-based legacy architecture; used only for SERP gap analysis.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Secondary source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S279",
      "Date": "2026-08-25",
      "Source type": "COMPETITOR",
      "Organization": "Stanza",
      "Title": "MCP Architecture",
      "URL": "https://www.stanza.dev/concepts/mcp-architecture",
      "Version": "Search-result audit",
      "Claim supported": "Competitor page retaining initialization-centered architecture; used only for SERP gap analysis.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Secondary source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S280",
      "Date": "2026-08-25",
      "Source type": "COMPETITOR",
      "Organization": "MCP Server Spot",
      "Title": "MCP Glossary",
      "URL": "https://www.mcpserverspot.com/learn/fundamentals/mcp-glossary",
      "Version": "Search-result audit",
      "Claim supported": "Competitor glossary using legacy session terminology; used only for SERP gap analysis.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Secondary source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "PERIODICALLY REVIEW"
    },
    {
      "ID": "S281",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "SEO Guide for Web Developers",
      "URL": "https://developers.google.com/search/docs/fundamentals/get-started-developers",
      "Version": "Current guidance",
      "Claim supported": "Unique title/meta, semantic HTML and DOM-accessible content.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "ID": "S282",
      "Date": "2025-12-10",
      "Source type": "SEO_GUIDANCE",
      "Organization": "Google Search Central",
      "Title": "Ask Google to Recrawl Your URLs",
      "URL": "https://developers.google.com/search/docs/crawling-indexing/ask-google-to-recrawl",
      "Version": "Current guidance",
      "Claim supported": "URL Inspection, sitemap submission and no guarantee of immediate indexing.",
      "Historical claim supported": "",
      "Research packages": "5",
      "Authority": "Primary or first-party source",
      "Notes": "Normalized from the checksum-verified research/5 architecture package.",
      "Durability": "LIVE-CHECK REQUIRED"
    },
    {
      "Date": "2026-08-25",
      "Source type": "DOCS",
      "Organization": "Cursor",
      "Title": "Model Context Protocol in Cursor CLI",
      "URL": "https://cursor.com/docs/cli/mcp",
      "Version": "Live documentation checked 2026-08-25",
      "Claim supported": "Cursor CLI is a distinct MCP-consuming surface that shares MCP configuration with the Cursor editor.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze for package 5",
      "Authority": "Primary or first-party source",
      "Notes": "Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.",
      "Durability": "LIVE-CHECK REQUIRED",
      "ID": "S283"
    },
    {
      "Date": "2026-08-25",
      "Source type": "DOCS",
      "Organization": "Zed Industries",
      "Title": "Model Context Protocol in Zed",
      "URL": "https://zed.dev/docs/ai/mcp",
      "Version": "Live documentation checked 2026-08-25",
      "Claim supported": "Zed documents current MCP server configuration and its host-side MCP integration.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze for package 5",
      "Authority": "Primary or first-party source",
      "Notes": "Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.",
      "Durability": "LIVE-CHECK REQUIRED",
      "ID": "S284"
    },
    {
      "Date": "2026-08-25",
      "Source type": "DOCS",
      "Organization": "Zed Industries",
      "Title": "Worktree Trust",
      "URL": "https://zed.dev/docs/worktree-trust",
      "Version": "Live documentation checked 2026-08-25",
      "Claim supported": "Restricted Mode blocks project-configured language and MCP servers until trust; globally configured servers are outside that gate.",
      "Historical claim supported": "",
      "Research packages": "Editorial supplemental freeze for package 5",
      "Authority": "Primary or first-party source",
      "Notes": "Added during the 2026-08-25 first-party product-source review; not part of the byte-exact research/5 archive.",
      "Durability": "LIVE-CHECK REQUIRED",
      "ID": "S285"
    }
  ]
}