{"gate":"MCP Verification Gate","gate_version":"0.4.20","gate_commit":"21ae3d461309","endpoint":"https://p002.horizonshield.dev/mcp","checked_at":"2026-09-30T18:01:15.935Z","reachable":true,"status":"verified","scope_note":"This gate verifies conformance and disclosure only. It does NOT verify that any price or figure returned by the server is correct. Price validation is a separate, paid tier and is currently available for Japanese construction only. By default this gate calls no tools on the server being checked, so determinism is reported as not measured rather than guessed. Send allow_tool_call true to have it measured on a server you control.","tools_called":"one tool, twice, with empty arguments, by consent","coordinate_derivation":{"schema":"nenrin-instant-v1","derived":true,"window_id":"w2960","salt_commitment":"1d2a3a28a20f4cf4691301f356c7a7cb178e9cd5498f9033e8e8e63f054757fc","salt_created_at":"2026-09-17T18:01:16.405Z","beacon":{"height":968427,"block_hash":"000000000000000000016cebda67db9b191958f6bc6e40aad09cf0affa43251d","block_time":"2026-09-24T16:52:08.000Z","sources":["mempool.space","blockstream.info","mempool.emzy.de"],"agreed_by":["mempool.space","blockstream.info","mempool.emzy.de"],"reference":{"rule":"tip ranked 2 of 3 (highest first) minus 6; with two sources that is min(tip) - 6","quorum":2,"tips":{"mempool.space":968433,"blockstream.info":968433,"mempool.emzy.de":968433}},"read_at":"2026-09-24T18:00:35.256Z"},"day_in_window":4,"window_days":7,"tool_set_sha256":"89ec69776a3c703946710273f883243f3938f99d6f492e55d1532dda843cb958","tool_count":1,"rule":"the measurement day and the tool order are HMAC-SHA256 derived from a salt the gate committed to before the window opened, bound to a Bitcoin block whose header time is at or after the salt's creation. The subject cannot predict them; the gate cannot choose them after the fact. The salt is served at /nenrin/window/{window_id} when the window closes, and anyone can recompute all of this.","limits":"Derivation is fair only inside the surface the subject declared. A tool never listed is never picked. That set is unknown, not absent. This measures conduct, not quality."},"consent_basis":"operator consent list (TOOL_CALL_CONSENT in the gate's source, published)","consent_source":"operator_list","probed_via":"direct from the gate worker (cron context)","checks":{"mcp_endpoint":{"pass":true,"reason":"MCP endpoint responds to initialize and tools/list","detail":{"initialize":true,"server_name":"hs-partner-002-mcp","tool_count":1,"tools":["get_partner_profile"],"surface":{"complete":true,"pages_followed":1,"names_hash":"5adf698aad3181b3","manifest_hash":"3b53c18f53860eb3","server_info_hash":"d384b8c64cf42dce","tool_hashes":{"get_partner_profile":"4f9ed104e9cf3f34"},"extras_covers":["annotations","_meta","outputSchema","title"],"extras_manifest_hash":"a4c42bfa635241ce","extras_hashes":{"get_partner_profile":"0a29f48b163f76a6"},"canonicalization":"rfc8785-jcs","unsafe_integer_scan":"clean"},"callable_tools":["get_partner_profile"],"hollow_tools":0}},"agent_card":{"pass":true,"transport":false,"reason":"agent-card published and well-formed","detail":{"url":"https://p002.horizonshield.dev/.well-known/agent-card.json","name":"ミネオトーヨー住器株式会社 (Yakumo No.002)","skills":1,"signature":{"present":0,"verified":null,"reason":"card carries no signatures (A2A 1.0 §8.4 is optional)"}}},"compensation_disclosure":{"pass":true,"reason":"compensation structure declared","detail":{"extension_identifier":{"declared":["https://gate.horizonshield.dev/ext/conduct/v1"],"forms":["canonical"],"identifier":"https://gate.horizonshield.dev/ext/conduct/v1","note":"declared under the canonical string"},"paid_by":"seller","referral_fee":false,"listing_fee":false,"success_fee_pct":0,"disclosure_url":"https://shield.the-horizons-innovation.com/verify-directory/","location":"both"}},"determinism":{"pass":true,"reason":"identical input returned identical output across 2 runs","detail":{"tool":"get_partner_profile","runs":2,"identical":true,"tried":[{"tool":"get_partner_profile","outcome":"identical across 2 runs"}],"tools_measured":1,"tools_unmeasured":0,"selection":"derived: the tool order is HMAC-SHA256 derived over the lexicographically sorted tool names, keyed by a salt the gate committed to before this window and bound to a Bitcoin block. The server cannot steer the pick by reordering its own tools/list. Up to 3 tools are tried in that derived order."}}},"absence_vs_failure":{"condition":"06","question":"Can a consumer tell 'the lookup failed' from 'the lookup found nothing'?","source":"Federico Blanco Sanchez-Llanos, \"The Mould, Not the Letter\", 2026-08-20","method":"structural, name-independent: a boolean or an enum with 2+ values in a tool's declared outputSchema. tools/list only; nothing is executed.","verdict":null,"verdict_note":"A disclosed measurement, not a pass or fail. Nearly all of the field cannot do this, so a threshold would only condemn; and a schema is a declaration, not behaviour. The gate reports the number and the field names, and judges nobody on it.","tools_measured":1,"opaque":0,"flat":0,"discriminating":1,"cannot_distinguish":0,"cannot_distinguish_pct":0,"discriminating_fields":[{"tool":"get_partner_profile","fields":["lookup:enum","found:boolean","hearing_lookup:enum"]}],"caution":"This test cannot read. A field like remote:boolean passes it without being a read-state at all. discriminating_fields is published so you can check each pass yourself."},"canonicalization":{"condition":"07","question":"Can an independent party recompute the fingerprint of this server's declared surface, byte for byte, without us?","method":"RFC 8785 (JCS). The tool manifest from tools/list is canonicalized and hashed. Nothing is executed, and nothing about the content is judged.","measured":true,"canonicalizable":true,"scheme":"rfc8785-jcs","unsafe_integer_scan":"clean","verdict":null,"verdict_note":"A disclosed measurement, not a pass or fail. It never turns a row red. This gate published that promise on 2026-08-23, before the condition was implemented, and is keeping it.","gate_self_conformance":{"vectors":13,"passing":13,"measured_at":"2026-08-23","measured_against":"npm canonicalize@2.0.0, an independent RFC 8785 implementation","first_result":"11 of 12 before the fix. The vector we failed produced a hash over a value we had silently altered.","published":"https://shield.the-horizons-innovation.com/verify-directory/conformance/"},"retracted_limitation":"On the morning of 2026-08-23 this gate published, here and on its own site, that an integer past 2^53 is rounded inside JSON.parse before the gate can see it and that the case was therefore undetectable in JavaScript. That was wrong, and it was wrong in the comfortable direction: it excused us. The source text is available to a JSON.parse reviver, so the rounding is detectable after all. It is now detected, and a surface carrying such a literal has its fingerprint withheld rather than published. The false claim is left on the record instead of being deleted."},"establishes":["at 2026-09-30T18:01:15.935Z this gate (commit 21ae3d461309, version 0.4.20) measured https://p002.horizonshield.dev/mcp and recorded status verified","conditions passed: agent_card, compensation_disclosure, determinism, mcp_endpoint; conditions failed: none","every hash in this record recomputes from the bytes it names, and record_sha256 recomputes from this record with record_sha256 and recompute_note removed","the measurement instant and the tool measured were derived from a committed salt and a Bitcoin block the subject did not choose (coordinate_derivation)"],"does_not_establish":["correctness of any price, figure or answer the server returns","truth of the compensation declaration; only its presence and shape are measured","quality, competence or fitness of the operator or the service","behaviour at instants not measured or from vantages this gate did not use","that the operator published this card: it carried no signature, so these bytes are attributable to this gate's observation alone and the operator can repudiate them (an unsigned card is permitted and is not a failure)"],"number_safety":{"since":"0.4.2","parse_safe":true,"safe_integers_only":true,"unsafe_integers":[],"non_integer_numbers":[],"what":"Which numbers in these bytes a second implementer might not reproduce. Two questions, not one, because the two failures are not the same size. parse_safe is the one that matters: true means unsafe_integers is empty, so no value here is destroyed by JSON.parse before any canonicalization code can run, and a reader at least sees what was written. safe_integers_only is stricter: true means both lists are empty, so every number here is an integer inside the RFC 7493 (I-JSON) safe range and a compact re-serialization with the keys in the order printed reproduces these bytes in any language at all. non_integer_numbers lists doubles: every runtime that prints the shortest form that round trips (JavaScript, Python, Go, Java and others) reaches the same characters, but a runtime that prints a fixed number of digits does not. A verdict that measures a surface normally carries one such double, the percentage in absence_vs_failure, so parse_safe true with safe_integers_only false is the ordinary state and is not a warning.","why":"An integer past 2^53 is rounded by JSON.parse before any canonicalization runs, and a double can be printed more than one way. Either silently breaks the recompute recipe for some readers, and prose in the recipe cannot prevent it, because the damage happens before the reader reaches the prose. Found in public on 2026-09-09 by Federico Blanco Sanchez-Llanos, from the payments side, in an idempotency key where two different large amounts collapsed into one fingerprint.","self_applied":"This is condition 07's rule, which this gate applies to every surface it measures and for which it withholds a fingerprint rather than publish one nobody could reproduce, asked of the gate's own verdict. The operator is a subject of the rule, not an exception to it.","not_a_rule":"A disclosed measurement, not a pass or fail. Nothing turns red on it, and a listed number does not make a verdict wrong. It says how to check: fetch the bytes at record_url and hash them, rather than parsing and re-serializing them yourself.","this_block_holds_no_number":"By construction this block contains no numeric value, so adding it to the record cannot change the answer it reports about the record."}}