Four bounded tools
Each tool performs one concrete public task. There is no generic tool able to browse internal routes, execute code or modify an origin.
The deployed MCP server exposes audit, methodology, Registry and OKF through small tools and versioned resources. It is stateless and has no access to owner information.
Inspect the public MCPEach tool performs one concrete public task. There is no generic tool able to browse internal routes, execute code or modify an origin.
Capabilities, methodology, OKF and readiness use stable identifiers. Arbitrary paths and private parameters are rejected.
The server needs no OAuth because it protects no private data; it also keeps no memory, writes no data, deploys no changes, charges no money and never acts for an owner.