SENTINEL SIGNALVERIFY
METHODOLOGY CHANGELOG

MCP Verify methodology changelog

Historical scoring corrections, verdict-consistency fixes, and methodology changes for MCP Verify, pulled from the public changelog.

About this page

This page lists releases that changed how scores, verdicts, or evidence are computed or reported -- not every release. General product changes are in the full changelog.

Scoring and methodology changes by release

Each entry links a version to the scoring/verdict/evidence-computation behavior it changed.

VersionDateChanges
1.0.5372026-08-11
  • Snapshot-churn-risk verdict no longer reports "low" / "no material churn detected" when there was no prior validation to compare against at all; it now reports the assessment as unavailable.
1.0.5362026-08-10
  • Write-action governance no longer reports "Safe to publish" or "No high-risk tools were detected" for a server whose write-action safety was never actually assessed; it now reports the assessment as unavailable.
  • The executive verdict (Block/Allow decision) no longer recomputes its own independent blocker thresholds; it now derives from the same canonical production-readiness verdict every other surface uses.
  • Comparison-template pages render the same canonical verdict label text as the server profile page, instead of an independently re-derived variant.
  • Ownership/claim status is now derived from one shared function everywhere it is shown.
1.0.5352026-08-10
  • Change detection (auth mode, write-action surface, tool snapshot) now compares against the most recent validation run that actually observed a tool surface, instead of the immediately-adjacent run -- a non-enumerating baseline no longer fabricates false high-severity alerts that degrade the production verdict.
  • "Validation history" no longer shows a false 0 tool count for a run that never fetched a tool surface.
  • Publishability status for Claude now weighs `admin_refresh_required` consistently instead of silently ignoring it.
  • "Client compatibility" summary and gate-details checklist now derive from the same blocker list.
1.0.5332026-08-10
  • A server no longer reads "Metadata only" after a real validation run was attempted and failed; a validated-and-failing server now reports a distinct "Failing" verdict.
  • Publishability profiles now correctly report "blocked" when the underlying client-compatibility profile is blocked, instead of always downgrading to "caution".
  • Six security-posture score components are now excluded from scoring, rather than credited a fixed partial score, when the underlying tool surface was never observed.
  • Prompt Contract and Resource Contract score components now zero-anchor a `skipped` check status the same as `missing`, instead of crediting it as if it had run successfully.

See the full product changelog for all releases, or Methodology for what the score means today.