aziel-runtime
This server is Aziel Runtime — an MCP orchestration suite that routes catalog Softwares through a single FragGate door to run in-process engines, mint receipts, and manage sessions/ledgers.
First call — Softwares: reads the catalog of product cards (name, slug, ops, worker_home) so you can pick a slug. No args.
FragGate door (discover → route → refuse):
fraggate_listlists hashed registry names/digests and allowlists;fraggate_describeinspects one card (live/stub/local_only, ops, digest);fraggate_callexecutes a slug+op through the full pipeline (Lamb Lens, DecisionGATE, AZPIPE, ChainLock, TemporalLock, ForgeReceipts) withconfirm,dry_run, andbackgroundjob support.Registry proof:
fraggate_verifychecks a name, slug, or 64-hex digest against the hashed registry (entry or registry-level match/mismatch).DecisionGATE:
decisiongate_checkruns the five sequential gates on a proposal without executing a product; also runs automatically before anyfraggate_callexec.Library lookup:
library_lookupsearches Aziel Digital Library papers/cites/examples/skills (ops: search, example, skill, health).Adaptive memory (AKM-TRIAD):
memory_observe,memory_resolve,memory_calibrate,memory_recall(ranked beliefs, capped 16),memory_get(node/history/calibration explain). Belief is not truth;authorizes_action=false.ChainLock ledger:
chainlock_append(fact stamps on 10 named chains),chainlock_tip,chainlock_recall(depth 0–5 grounded facts),chainlock_verify(fail-closed integrity + LOCKSET),chainlock_seal(writes local LOCKSET).Node mesh (QNM):
mesh_status,mesh_enable,mesh_disable(refused),mesh_join,mesh_heartbeat,mesh_leave,mesh_nodes,mesh_broadcast(hash receipt only, never upload).Advanced/internal session plumbing:
runtime_session_open/policy/exec/receipt/receipts/closefor raw open→policy→exec→receipt→close sessions (6h TTL, cap 64), plusruntime_run(raw exec façade) andruntime_manifest.Bootstrap helpers:
runtime_skill(agent how-to),runtime_bundle(all product skill URLs),runtime_pull(one hub product card).Safety model: unknown names refuse
FG-HALLUC-TOOL, stubs refuseFG-STUB, local-only refusesFG-LOCAL-ONLY, writes requireconfirm=trueordry_run=true; results carry adisplayenvelope plus machineresult,receipt,engine_digest, andran_in.
The server runs on Cloudflare Workers and Durable Objects, which serve as the execution jail for vendored engines and the MCP/OpenAPI HTTP surface.
Lists DuckDuckGo AI / DuckAssist as a compatible AI client that can call the server's OpenAPI, MCP, or HTTP tools.
Lists Meta AI and FacebookBot surfaces as compatible AI clients/crawlers for the server's OpenAPI, MCP, or HTTP tools.
Mentions Flutter as part of the dual-surface human software install surface alongside the Worker and local install.
The project is hosted on GitHub and the coordinator applies repository metadata via gh repo edit; GitHub is the source repository, not an external service integration.
Lists Google Gemini / Vertex AI and Google-Extended/GoogleOther crawlers as compatible AI clients that can call the server's OpenAPI, MCP, or HTTP tools.
Lists Google Gemini / Vertex AI as a compatible AI client that can call the server's OpenAPI, MCP, or HTTP tools.
Lists Meta AI and Meta-External* crawler surfaces as compatible AI clients that can call the server's OpenAPI, MCP, or HTTP tools.
Lists ChatGPT (GPT Actions / OpenAI) as a compatible AI client that can call the server's OpenAPI, MCP, or HTTP tools.
Lists Perplexity as a compatible AI client that can call the server's OpenAPI, MCP, or HTTP tools.
Provides TemporalLock stamping inside the FragGate execution pipeline, adding temporal lock receipts to calls and ChainLock seals.
Provides azieltether as a catalog engine for tether declaration, cutting, and listing operations through the FragGate door.
Lists TikTokSpider as an allowed crawler surface for the server's public content.
Explicitly instructs not to invent Zenodo DOIs, so Zenodo is not an integration target.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@aziel-runtimeRun decisiongate_check on 'Ship the catalog.' with evidence 'OpenAPI 3.1'."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
aziel-runtime
Aziel Runtime starts at Softwares, FragGate, and the library. Softwares picks a slug. FragGate is the single exec door. library_lookup searches library papers and cites. Install on Glama, then call Softwares, pick a slug, and fraggate_call. 40+ research tools run through that one door. Every call can leave a receipt.
Install (remote first)
Public MCP — no API key:
https://aziel-runtime.vibelock.workers.dev/mcpTransport: Streamable HTTP. Full client recipes: docs/AGENTS.md.
Registry: io.github.AzielEliab/aziel-runtime · Glama: Install
Access
Public: Softwares, FragGate list/describe/call, library lookup — no auth
Glama hosted: optional Install Server. Glama hosted-tool meters stay separate from Worker
GET /v1/usesLocal stdio: clone +
cli/mcp-stdio.mjs(dev path; keep below the remote URL)
First tools
Softwares /
fraggate_listfraggate_describe→ pick a slugfraggate_call(useconfirm: truewhen required)
Related MCP server: openapi-atlas-mcp
How to use
Click Install / Add to Glama (also
https://glama.ai/mcp/servers/@AzielEliab/aziel-runtime).In any MCP client, call Softwares (tools/list name Softwares). The door runs first. Pick a slug, then
fraggate_call.library_lookupsearches library papers and cites. ChainLock, TemporalLock, and ForgeReceipts stamp when the call needs a ledger.confirm=truewrites.dry_run=truepreviews and writes nothing.background=truereturns Running until a receipt hash exists. Done only with that hash.tools/liststays 36.
Diagnostics, if needed: fraggate_list → fraggate_describe {name} → fraggate_call {name, op, payload, confirm:true}.
Worker remote: https://aziel-runtime.vibelock.workers.dev/mcp
Example first call: Softwares {}, pick a slug, then fraggate_call with { "slug": "foldlock", "op": "fold-preview" }. library_lookup with { "q": "Florence", "op": "search" } is a library paper or cite. Also: decisiongate_check with a short proposal and dry_run:true, or forgereceipts receipt for a completed task.
MCP tools/list is 36 tools. FragGate is the single door. Public connect is the remote URL in Install (remote first) (Streamable HTTP, no API key). Glama Install Server is optional and meters separately from Worker GET /v1/uses. Local stdio stays last. Compatible AI clients are listed below. Author: Aziel Eliab.
Designed purpose
Aziel Runtime (aziel-runtime) is a node-meshed orchestration suite of MCP-connected software designed to route catalog Softwares through the FragGate door, mint receipts, and coordinate mesh presence. Use it to list, describe, and call product operations over MCP or OpenAPI, then keep the returned receipt. It exists so each Softwares product stays a separate engine behind one door.
Start
node cli/aziel-runtime.mjsnode cli/aziel-runtime.mjs session open --localnode cli/aziel-runtime.mjs session status --local
The terminal prints a short summary. Add --json for the machine object. Help: node cli/aziel-runtime.mjs --help. The same three steps are in RUN.txt.
Softwares purpose copy (one_line + description) is the designed-to-do addendum on GET /v1/software (src/software-copy.js). Hubs refresh from that route.
FragGate is THE single public executable door (fraggate_list → fraggate_describe → fraggate_call). Softwares catalog is Plain → Gate → Lock; hubs refresh from GET /v1/software. Humans use Softwares in the Worker UI on the VibeLock host (browser / PWA) — no download required. Agents use OpenAPI/MCP. Optional suite pack JSON remains at /download. NodeMesh / QNM read-only suite-presence is ON by default; GET /v1/mesh never enables radios beyond that.
Version 2.0.0-rc1 is the certification-point freeze (not a feature dump): public contract, clean-room reproducibility, and external adversarial pack under docs/2.0/. No intentional behavioral breaks from 1.9.3. Remain-OFF untouched. Crawler surfaces keep the abstract above; changelog stays below. 1.9.3 closed remaining AZRT-1.9-GAPS-CLOSE items (isolate AZ-OS ethics session VFS; isolate-safe Ask Jeeves; binding-gated media-run; published independent-validation attestation path — not a third-party lab). 1.9.2 bound Browser Rendering and live D1 MASTER. 1.9.1 closed AZRT-1.9-GAPS-CLOSE isolate-safe verify. 1.9.0 closed AZRT-1.9-CLOSE-1.0. 1.7.11 is the SEO-clarity heritage that locked that lead copy.
Kernel: AzielEliab/fraggate (FG-0.1)
Try on Glama is the primary public host / discovery / install listing (also https://glama.ai/mcp/servers/@AzielEliab/aziel-runtime). Worker origin stays the execution / OpenAPI / MCP HTTP surface.
Entity graph (locked): Person @id https://www.azieleliab.com/#aziel · Runtime SoftwareApplication @id https://www.azieleliab.com/runtime#runtime. Worker origin is the execution endpoint (url). relatedLink is the Glama discovery / install host. Identity Aziel Eliab only.
open → policy → exec(slug, op, payload) → receipt → close
Agents should not narrate that chain. Prefer fraggate_list → fraggate_describe → fraggate_call { name, op, payload }. Hubs/clients: GET /v1/software.
1.3.0 vendored portable engines (ark, azai Lamb check, azclce, decisiongate, foldlock, zsolver) and ran them in this isolate.
1.2.0 was a session/receipt runtime: exec still upstreamFetched product Workers. Those receipts were not “this process ran FoldLock.”
1.1.0 was catalog + pull + proxy that started calling itself a runtime. Those front doors stay. They are not exec.
For every catalog slug session exec loads a vendored module, computes engine_digest = SHA-256 of that artifact’s bytes, runs the primary compute op inside this Worker isolate (the jail) or a local CLI jail, wipes scratch buffers, and the receipt includes engine_digest, engine_slug, engine_op, ran_in. GET /v1/health engine_slugs equals true_engine_slugs. Ops that literally cannot run without product-Worker bindings (KV / D1 / AI / live media) stay honest per-op proxy_fallback — the slug itself remains a true engine.
Cloudflare’s Worker / Durable Object isolate is the jail. No extra guest isolate is claimed. engine_digest is still required.
Hosted / in-process AZAI is still protocol mirror + Lamb check (Service → Clarity → Peace). The local core is standalone. Ollama is optional SLOT, not the identity.
Any OpenAPI-, MCP-, or HTTP-tool-capable assistant imports this OpenAPI file — then use fraggate_call. Session tools and runtime_run are advanced/internal. /p/{slug}/{op} is proxy only and is not the agent default path.
Author: Aziel Eliab
Identity: Aziel Eliab (primary). Also known as Aziel Elroi Eliab (alternateName / aka only).
License: Apache-2.0
Version: 2.0.0-rc1
2.0 pack: docs/2.0/ (contract freeze; self-test ≠ third-party lab)
Role: engine-runtime (layer: catalog+pull+proxy+session+in-process-engines+fraggate)
Door: fraggate
Primary host: Try on Glama
Worker (execution / OpenAPI / MCP HTTP): aziel-runtime → https://aziel-runtime.vibelock.workers.dev/
Entity parent: https://www.azieleliab.com/runtime
Library mirror: https://www.azielcorpuslibrary.net/runtime
Rose-star brand mark: https://aziel-runtime.vibelock.workers.dev/sigil.png
Packaging: Worker session + in-repo CLI (node cli/aziel-runtime.mjs) + stdio MCP (node cli/mcp-stdio.mjs / npm run mcp). No counted runtime tarball.
Forks are welcome and always allowed. Do not invent Zenodo DOIs.
Inspect the code (not the crawler files)
Behavior | Source | Tests |
FragGate list / describe / call |
| |
MCP |
| |
Session open → policy → exec → receipt → close |
| |
Software catalog |
| |
Offline receipt hash |
|
Full path map: docs/2.0/INSPECT.md. How to run tests: docs/2.0/TESTS.md. Privacy: docs/DATA.md. Review / agent-assisted commits: docs/GOVERNANCE.md. wrangler.toml main is src/index.js (unminified). Cloudflare may bundle that same module for deploy — the reviewed artifact is this tree.
Compatible AI clients
Assistants / clients that can call OpenAPI, MCP, or HTTP tools:
ChatGPT (GPT Actions / OpenAI)
Grok (xAI)
Venice
Claude (Anthropic Desktop / custom tools)
Cursor (MCP)
Glama (Install Server / MCP)
Perplexity
Microsoft Copilot / Bing
Google Gemini / Vertex AI
Mistral
Meta AI
Apple Intelligence / Applebot surfaces
Amazon Q / Amazonbot tooling
DuckAssist / DuckDuckGo AI
You.com
Cohere
plus other MCP/OpenAPI-capable assistants
Practical Add-to steps below cover ChatGPT, Grok, Venice, Claude Desktop, and Glama / Cursor MCP. Do not invent step-by-step for every crawler.
Crawl / SEO Allow set on robots.txt: GPTBot/ChatGPT, Venice, Grok, Google-Extended, GoogleOther, Google-CloudVertexBot, Claude(+Search/User), anthropic-ai, Perplexity(+User), bingbot, Meta-External*, Applebot(+Extended), Amazonbot, DuckDuck/DuckAssist, MistralAI-User, YouBot, CCBot, cohere-ai, cohere-training-data-crawler, Diffbot, AI2Bot(+Dolma), Timpibot, Petalbot, Bytespider, Omgili(+bot), FirecrawlAgent, ImagesiftBot, Cloudflare-AI-Search, FacebookBot, TikTokSpider, Baiduspider*, Yandex.
GitHub About (description / homepage / topics) is documented in docs/GITHUB.md so indexes see MCP, OpenAPI, and FragGate. Coordinator applies gh repo edit from that lock.
Websites / Live sites
Try on Glama is the primary public host / discovery / install listing. This Worker homepage stays the API / MCP / OpenAPI execution surface. Human Softwares hubs are azieleliab.com, Aziel Corpus Library, and GodLock.uk. Sister archive: He Didn't Jump.
The Worker ships a FoldLock-packed library tip (index cite + sample MASTER + About Aziel) — not the entire live corpus. Verify via FragGate foldlock/pack-verify; open via aziel-corpus/tip-pack. Honesty: docs/corpus-fold-pack.md.
Every Worker launch (homepage, /about, every /p/{slug}, HTML Softwares/describe shells) includes product-specific #hashtag parts plus the same About Aziel block. Shared partial workerLaunchHtml. Product Workers inherit About Aziel + the fold tip by copy; hashtag parts stay local. Rule: docs/WORKER-LAUNCH.md.
Surface | URL |
Primary host / discovery / install | |
Official site | |
Runtime hub (entity parent) | |
FragGate kernel | |
Canonical GitHub | |
Runtime Worker / MCP / OpenAPI | |
Library mirror (reverse-proxy) | |
Aziel Corpus Library | |
Aziel Eliab (library) | |
Software page | |
GodLock.uk | https://godlock.uk — https://godlock.uk/AzielEliab — https://godlock.uk/software |
He Didn't Jump (sister archive) | |
Trades-Runtime (sister product, cite-only) | Version 0.4.9 (live |
Repos | https://github.com/AzielEliab/aziel-corpus · https://github.com/AzielEliab/godlock · https://github.com/AzielEliab/hedidntjump.com · https://github.com/AzielEliab/trades-runtime |
Donate (canonical) |
Glama Install Server is live (Try on Glama). Glama release 2.0.11 (Install Server ON, Auto-Release ON). Worker / server package stays 2.0.0-rc1. Public connect is remote POST https://aziel-runtime.vibelock.workers.dev/mcp first. Glama Install Server is optional; its hosted meters stay separate from Worker GET /v1/uses. Local stdio stays last. See docs/GLAMA.md.
Public identity: Aziel Eliab only. Do not invent Zenodo DOIs.
Dual surface (product law)
Agent / MCP — Software runs through the agent. Show
display.title/display.summary/display.fields, then take the next input. Session, OpenAPI, and HTTP plumbing stay invisible unless asked for. One door — discover, route, refuse. Download viaGET /v1/update/check?slug={slug}&version={installed}→download_urlorGET /v1/pull/{slug}. BareGET /v1/update/checkis not a check. Mesh-resident azcorpus + azlibrary website designs download fromGET /v1/softwarewebsite_designs(open for all AI clients). Upload/ingest/receipt viafraggate_call(azbrowserairlock_ingest, peacelockupload_envelope, forgereceiptsverify, miragegridverify-receipt/bridge). azlibrary upload is API token only — never embed the secret. Same ops on/openapi.json.Human software — This Worker UI, local install, and counted
/downloadremain complete developed software. Fluttermobile/is not vendored in this repo.
Cold multi-shelf (COLD-MULTI-SHELF-1.0)
Runtime cites the same honesty as live corpus GET /shelves (corpus#96). GET /shelves · GET /v1/shelves · /cite.json shelves. Person @id https://www.azieleliab.com/#aziel.
Plane A LIVE: 5 published surfaces (4 CF hubs + GitHub) / 2 family radii. One independent live (cf-github). Plane B SLOT: Codeberg https://codeberg.org/AzielEliab/aziel-lockset-tip hash-verify PASS still SLOT; archive.org PASS https://archive.org/details/aziel-lockset-tip + https://archive.org/details/aziel-lockset-tip_202609 (same blast_radius archive-org; pack b549362c0736ddb54ddc488812327c464e0da1167281f92fd1a4263eedf5df37) still SLOT; Framagit URL null (third ALL-TARGETS) Zenodo tip-pack SLOT (CNS-ZENODO-NOT-LIVE); doi null. Plane C USB SLOT until CNS-OPERATOR-ATTEST. This Worker is the same Plane A tunnel. No visible 15:20.
Home origin (ORIGIN-CUTOVER-1.0)
AZNet P3. Survival layers serve AZNet (aznet, AZN-WP-0.1). sidenet is that side-net, not a separate brand. L0 stays unbroken. A mini-PC path beside the live Cloudflare hubs stays SLOT: no rented DNS, no live DNS change, no deposited bytes, no invented hostname or IP. Phoenix is local wait (REHEAL-1.0), not a public hostname coming back. Independent live count stays 1. Softwares stay frozen. Paper: ORIGIN-CUTOVER-1.0.
Cap-7 semantic bridge (not ICANN)
Cap-7 is the MirageGrid auto-generate .az layer. It duplicates the four hub sites and shifts with StaticLock (catalog product StaticClock, slug staticclock) and MirageGrid cloak, paired with AZVPN. design_of: hub_designs. resolves_to_hub: false on Cap-7. Standard internet does not reach Cap-7. Real duplications: azgrid, azcloak, azvault, azshift. False sites: azbooth, azflag, azstandby. Factory duplication cite is LIVE. Internet reaches the AZ domains (AZ.AzielEliab.AZ, AZ.AzielCorpusLibrary.AZ, AZ.Godlock.AZ, AZ.HeDidntJump.AZ) through azieleliab.com, azielcorpuslibrary.net, godlock.uk, and hedidntjump.com. Those drop-ins are public_icann: true and resolves_to_hub: true, shuffle once to one of four, stand alone, and freeze after the hubs go down. Live nodes anchor them. Cap-7 public_icann: false. The Cap-7 factory is not a public ICANN registrar. Four hub mirrors and three decoys are not per-node .aziel slots. geo-target, session-stick, and egress-rotate are LIVE on the Cap-7 control plane (region label, sticky mesh node and factory land, land rotate among 7 sites). They are not a public egress IP, not a residential IP, not a Cloudflare geo-exit pool, not a sticky public IP, not packet forwarding, and not AZVPN. The public MirageGrid Worker Cap-7 control plane is LIVE (/v1/egress and /v1/planned). vpn-hop, hop, tunnel, and mesh stay stub. Not a fifth product. AI pulls metadata from MirageGrid Worker /bridge or GET /v1/mesh/az-generator. Update shuffle: fraggate_call { slug: "miragegrid", op: "shuffle" } lands one mesh name (factory land LIVE; not a public HTTPS door). No live AZ-GEN registrar. No ICANN .az ccTLD purchase. No visible 15:20. GET /v1/mesh never enables radios. Mesh browse: AZNet + AZBrowser via FragGate.
Plane N and Plane P
Plane N is this Cap-7 / .aziel name plane. It is not an ICANN registrar and not a public egress IP. Plane P is the separate node-mesh packet path (devices as nodes). WARN-5 is STANDS-until-demonstrated, not a permanent ceiling. Carrier prefer order on that path is LAN, Wi-Fi, Bluetooth, RF, then photon light flashes. RF and photon refuse when the hardware is absent. No mock LIVE. Plane P is not claimed as LIVE public egress. The public door stays NOT-READY / FG-STUB. Local LAN discovery is LIVE-when-armed and the peer tunnel is LIVE-when-session. Local store-forward is LIVE-when-three-local-nodes / fixture. A phone can join that local node over the LAN beacon and sealed peer session (qnm-node/mobile/, paper TRACK2-MOBILE-JOIN-1.0). mobile_client stays present-not-demonstrated. The phone is a client of the local node, not an app-store release, and not alt-internet LIVE. Wi-Fi on the phone is the path to the LAN socket. It does not mark a Wi-Fi, RF, or photon exchange. alt_internet_live is false. WARN-5 is not closed. AZVPN stays the suite VPN and is not MirageGrid. Papers: PLANE-P-D2D-1.0, D2D-CARRIERS-1.0.
FragGate door
Public MCP tools/list is 36 live tools. First call: Softwares (tools/list name Softwares). The door runs first. ChainLock, TemporalLock, and ForgeReceipts stamp when the call needs a ledger. Diagnostics stay fraggate_list → fraggate_describe → fraggate_call (foldlock / fold-preview, or decisiongate_check with dry_run=true). The same list includes runtime_skill, fraggate_verify, library_lookup, suite mesh_*, append-only chainlock_* and memory_* (diagnostics and belief, not a pre-call), and catalog helpers. runtime_run and runtime_session_* are advanced/internal. Ledger ops stamp ChainLock on the acts chain, then TemporalLock and ForgeReceipts. fraggate_call reports those three from the pipe when a real hash exists. Lamb Lens, SweepGate, Sentinel, and RoseClock run inside that pipe. Reads do not stamp ChainLock, TemporalLock, or ForgeReceipts.
Every catalog product is a hashed registry entry (name, slug, digest, status, public ops). Status is live | stub | local_only.
stub_ops / stub_op_count are named refuse verbs (never hosted), not extra catalog Software engines. stub_count is registry entries whose status is stub (none after 1.9.0 — AZChat is LIVE+bound). EmbryoLock is a live catalog engine (live-with-local-destructive-boundary); wipe / scorch / unlock stay FG-STUB on the public mesh. FragGate live_count + local_only_count + stub_count === FragGate product_count. That product_count is registry entries, not the Softwares-tab count. Softwares includes veillock and whitestone. The public allowlist includes memory and mesh instead. software_nodes is the in-process product Worker fan-out (whitestone absent). GET /v1/software catalog_sets.equate is false. Do not equate those sets.
Live on the public mesh (via fraggate_call): every catalog Software product that makes sense on a public agent door — advisory / score / classify / gate / search / preview / render / verify / hash / receipt / game / overlay / route / status, plus the original five (DecisionGATE, GodLock, FoldLock, AZ-CLCE, Aziel Digital Library). VeilLock stays local_only (device-local camera/screen). MCP tools/list is those 36 names. Start on the FragGate door.
Stub ops (named refuse verbs, never execute): EmbryoLock wipe/scorch/unlock/encrypt/decrypt/initialize/login, ARK scorch/wipe/unlock/encrypt, WhistleLock send/mail/release, MirageGrid VPN-hop/hop/tunnel/mesh (geo-target / session-stick / egress-rotate are LIVE on the Cap-7 plane, not a public egress IP), AzielTether mesh-join/vpn/arm, VeilLock inject/intercept/facetime, AZ-OS exec/shell/lattice, AZAI blend/complete/chat, EmployeeLock court/judge, PeaceLock transcript/transcribe/motive/counterfactual/invent/waive-duty/bypass-duty, 4DMap truth_score/lumen_panel/invent_mark/backdate_class. Safe hosted ops on those products can still be live; the stub verbs refuse forever.
Unknown names refuse FG-HALLUC-TOOL and list the tools that do exist. DecisionGATE runs before any exec side effect; refuse is a typed ResultEnvelope + ledger tip (TemporalLock-shaped hash chain). Mesh is not claimed on this public surface.
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/fraggate
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/fraggate/list
curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/v1/fraggate/call \
-H 'content-type: application/json' \
-d '{"slug":"foldlock","op":"fold-preview","payload":{"text":"the cat and the dog"}}'Session (the actual cut)
SID=$(curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/v1/session/open \
-H 'content-type: application/json' -d '{}' | jq -r .session.id)
curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/v1/session/$SID/policy \
-H 'content-type: application/json' \
-d '{"allow_slugs":["azclce","foldlock"],"max_payload_bytes":8192}'
curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/v1/session/$SID/exec \
-H 'content-type: application/json' \
-d '{"slug":"azclce","op":"score","payload":{"r":"login button blue","d":"login form submits","p":"login button submits"}}'
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/session/$SID/receipt
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/session/$SID/receipts
curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/v1/session/$SID/closeA local exec receipt includes engine_digest, engine_slug, engine_op, ran_in: "aziel-runtime", result digests, and latency — not only an upstream HTTP status. close seals the chain; further exec is HTTP 409. Sessions expire after 6h (410/auto-close). Receipt cap is 64. Session mutate may require Authorization: Bearer … or X-Aziel-Runtime-Token when RUNTIME_TOKEN is set.
Local CLI (Worker client by default; --local writes a session file and prefers vendored engines; --jail runs the engine in a child Node process). The terminal prints a short summary. Add --json for the machine object:
node cli/aziel-runtime.mjs session open --local
node cli/aziel-runtime.mjs session policy --allow-slugs azclce,foldlock
node cli/aziel-runtime.mjs session exec azclce score \
'{"r":"login button blue","d":"login form submits","p":"login button submits"}'
node cli/aziel-runtime.mjs session exec foldlock fold-preview '{"text":"the cat and the dog"}'
node cli/aziel-runtime.mjs session receipt
node cli/aziel-runtime.mjs session closeProof script (local session log): bash scripts/demo-session.sh
Front doors (still useful — not exec)
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/skill
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/runtime.json
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/bundle
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/pull/foldlock
curl -s -A 'Mozilla/5.0' https://aziel-runtime.vibelock.workers.dev/v1/pull/foldlock/skillProxy (no runtime-owned receipt — not exec):
curl -s -A 'Mozilla/5.0' -X POST https://aziel-runtime.vibelock.workers.dev/p/azclce/score \
-H 'content-type: application/json' \
-d '{"r":"login button blue","d":"login form submits","p":"login button submits"}'Always send User-Agent: Mozilla/5.0.
Quick URLs
What | URL |
Homepage (HTML) | |
Skill | |
FragGate door | |
FragGate Worker UI + counted download | |
FragGate kernel | |
Machine manifest ( | https://aziel-runtime.vibelock.workers.dev/v1/runtime.json (public |
Session open |
|
Session exec |
|
Session receipt(s) | https://aziel-runtime.vibelock.workers.dev/v1/session/{id}/receipt |
Bundle | |
Pull one product | |
Pull product skill | https://aziel-runtime.vibelock.workers.dev/v1/pull/{slug}/skill |
Combined OpenAPI 3.1 | |
Authoritative software catalog (hubs) | |
FragGate software mirror | https://aziel-runtime.vibelock.workers.dev/v1/fraggate/software |
Client update check | https://aziel-runtime.vibelock.workers.dev/v1/update/check?slug={slug}&version={installed} |
Update manifest | https://aziel-runtime.vibelock.workers.dev/v1/update/manifest |
Machine catalog | |
How to cite | |
Ban / blocked-endpoint failover | https://aziel-runtime.vibelock.workers.dev/survival (aliases |
LLM crawler | https://aziel-runtime.vibelock.workers.dev/llms.txt (also |
Human help | https://aziel-runtime.vibelock.workers.dev/help.txt · |
Person (machine) | |
Who-is (machine) | |
robots.txt | |
sitemap.xml | |
sitemap-index.xml | https://aziel-runtime.vibelock.workers.dev/sitemap-index.xml |
MCP (JSON-RPC over HTTP, public, no OAuth) | |
MCP stdio (Glama / Claude Desktop) |
|
Glama listing | |
Health | |
API uses (no increment, no PII) | |
Stats / awareness rollup (read-only) | |
Ready | |
Rose-star brand mark |
GET /v1/pull?all=1 is an alias of /v1/bundle.
POST /p/{product}/{op} proxies to the product Worker /v1/{op} with the JSON
body. Service bindings are preferred; public *.vibelock.workers.dev is the
fallback. That path is a proxy, not session exec. Download counters are
not incremented.
This Worker is Worker-only (no counted runtime tarball). The local CLI lives
in-repo and is not a GitBaby /download package. Each product still has its
own counted /download.
How to cite: Eliab, Aziel. (2026). Aziel Eliab Runtime [Software]. Apache-2.0. https://aziel-runtime.vibelock.workers.dev/
Digital Library: Eliab, Aziel. (2026). Aziel Digital Library [Software]. Apache-2.0. https://www.azielcorpuslibrary.net/
Product Worker crawl template: docs/PRODUCT_SEO.md. QNM suite rollup: docs/NODE_MESH.md. Cross-network survival umbrella: docs/designs/CROSS-NETWORK-SURVIVAL-1.0.md. Companion NO-LIE / NO-REWRITE: docs/designs/NO-LIE-NO-REWRITE-1.0.md. Donate plan (cite-only, not a Softwares product): docs/designs/AZL-DONATE-1.0.md.
Donate (runtime + product Worker footer)
Canonical rails live on hubs: https://www.azieleliab.com/donate. Hub Donate pages include five QRs that encode payment URIs (BTC / ETH / LTC / XRP / DOGE). This runtime only links. Do not invent wallet addresses or tokens. Do not duplicate those five QRs on runtime or download-trackers.
Runtime Worker UI footer — one line:
Donate→https://www.azieleliab.com/donateProduct download-tracker Workers — same footer pattern:
Support the work→https://www.azieleliab.com/donate
This repo does not own product Workers. Copy that one line into those repos. Addresses stay operator paste on the hub.
Designs
Current suite software designs (AZL / SEC-FEAT / QNM-WP / NODE-OPS / AZL-DONATE-1.0 / CROSS-NETWORK-SURVIVAL-1.0 / NO-LIE-NO-REWRITE-1.0) plus LIVE fabric papers (CL-WP-0.4, AP-WP-0.2, SG-WP-0.1, LS-WP-0.1, RL-WP-0.1-runtime, QNS-CD-1.0, ACT-RECEIPT-1.0 — not Softwares-tab products): docs/designs/. Author: Aziel Eliab only. MCP chainlock_*. GET /v1/mesh never enables. QNS-CD-1.0 is the Quantum Node Signal packet-transfer coding design (photon QNS1 1.3). Implementation is local qnsd in AzielEliab/qnm-node. GET /v1/qns cites only — the public Worker does not proxy local via emit. Every /v1/software card carries qns_cd. Do not add QNS as a Softwares-tab product. ACT-RECEIPT-1.0 is the public four-field action-receipt mesh copy. The chain lives on corpus /receipts. GET /v1/receipts cites; append runs after FragGate list/call and POST /mcp when RECEIPT_APPEND_TOKEN is set (fail-open). Do not add ACT-RECEIPT as a Softwares-tab product. CROSS-NETWORK-SURVIVAL-1.0 is the umbrella survival law. If network and data die tomorrow, the chain survives on cold shelves (hosts / DOI / git / vault). Machine tip: /cite.json survival.tip and /llms.txt. Do not add it as a Softwares-tab product. NO-LIE-NO-REWRITE-1.0 is companion law under that umbrella (does not replace the machine tip): receipts that still hash; copies not all on one tunnel; no rewrite key; the network is never allowed to lie even to self-preserve. Do not add it as a Softwares-tab product. GET /v1/azpipe/arch cites the locked MASTER-33 strip (same payload as GET /v1/fraggate pipeline). Not a Softwares-tab door.
Add to ChatGPT (GPT Actions)
Create a GPT (or open GPT Actions).
Import from URL →
https://aziel-runtime.vibelock.workers.dev/openapi.jsonNo authentication. CORS
*.Ask the GPT to call Softwares (tools/list name Softwares). The door runs first. ChainLock, TemporalLock, and ForgeReceipts stamp when the call needs a ledger. Named live modules:
decisiongate_check,library_lookup. Diagnostics:fraggate_list, thenfraggate_call. Session tools andruntime_runare advanced/internal.
Add to Grok
Custom tool / OpenAPI: import
https://aziel-runtime.vibelock.workers.dev/openapi.jsonMCP remote:
POST https://aziel-runtime.vibelock.workers.dev/mcp
Methods:initialize,tools/list,tools/call.tools/listis 36 live tools. First call:Softwares(tools/list name Softwares). The door runs first. ChainLock, TemporalLock, and ForgeReceipts stamp when the call needs a ledger. Diagnostics:fraggate_list→fraggate_describe→fraggate_call.runtime_run,runtime_manifest, andruntime_session_*are advanced/internal.
HTTP/p/{product}/{op}stays a proxy. Public, no OAuth.
Tool results are{ display, result, ledger_tip? }— showdisplayto the user.
Add to Claude Desktop
Public connect is Streamable HTTP, no API key:
https://aziel-runtime.vibelock.workers.dev/mcpLocal stdio is the dev path after that remote URL. Claude Desktop claude_desktop_config.json (same shape as Cursor mcp.json):
{
"mcpServers": {
"aziel-runtime": {
"command": "node",
"args": ["cli/mcp-stdio.mjs"],
"cwd": "/path/to/aziel-runtime",
"env": {
"AZIEL_RUNTIME_URL": "https://aziel-runtime.vibelock.workers.dev"
}
}
}
}Restart Claude Desktop after updating the local config. Full client recipes: docs/AGENTS.md. Full stdio notes: docs/GLAMA.md.
Add to Glama
Public remote URL first. Glama hosted meters stay separate from Worker GET /v1/uses. Local stdio last.
Remote MCP —
POST https://aziel-runtime.vibelock.workers.dev/mcp(initialize,tools/list,tools/call). User-AgentMozilla/5.0. Public, no OAuth. Transport: Streamable HTTP.Install Server (optional) — Try on Glama (also
https://glama.ai/mcp/servers/@AzielEliab/aziel-runtime). One-click Install Server / Deploy. Glama release 2.0.11. Install Server ON. Auto-Release ON. Worker / server package stays 2.0.0-rc1. Hosted-tool meters are Glama's, not Worker/v1/uses.Local stdio (last) —
cli/mcp-stdio.mjsbridges to that same Worker/mcp.glama.json+DockerfileCMD["node", "cli/mcp-stdio.mjs"].
node cli/mcp-stdio.mjs
npm run mcp
docker build -t aziel-runtime-mcp .
docker run --rm -i aziel-runtime-mcp
# if the host resolver cannot see Cloudflare:
# docker run --rm -i --dns 1.1.1.1 aziel-runtime-mcpDefault bridge needs outbound DNS + HTTPS to *.vibelock.workers.dev / Cloudflare. A DNS miss is FG-DNS (remote:false). --local or AZIEL_RUNTIME_MCP=local is explicit in-process. Optional RUNTIME_TOKEN / AZIEL_RUNTIME_TOKEN when REQUIRE_TOKEN=1. Verify a real call hash: docs/2.0/INSPECT.md.
First call after connect: Softwares (pick a slug) → fraggate_call → library_lookup for library papers and cites. FragGate stays the single exec door. Diagnostics: fraggate_list → fraggate_describe → fraggate_call. Example: { "slug": "foldlock", "op": "fold-preview", "payload": { "text": "the cat and the dog" } }, or decisiongate_check with dry_run=true. tools/list is 36 live tools. ChainLock and memory are append-only.
Re-claim on the Glama Score tab after any glama.json change (maintainers = AzielEliab) so Schema and keywords refresh. Full steps: docs/GLAMA.md. Public identity: Aziel Eliab only.
Add to Venice
Custom HTTP tools / OpenAPI: import the same
https://aziel-runtime.vibelock.workers.dev/openapi.json.
Pull via GET /v1/bundle / GET /v1/pull/{slug}. Session exec is
POST /v1/session/{id}/exec. Proxy remains POST /p/{slug}/{op}.
Honesty banners
Every catalog Software slug is in-process.
engine_slugsequalstrue_engine_slugson/v1/healthand/v1/runtime.json. Binding-only ops stay per-opproxy_fallback.GodLock and MirageGrid are not VPNs and not anonymity networks. MirageGrid Cap-7 is a mesh-name factory and is not a public ICANN registrar. Cap-7 geo, sticky session, and land rotation are LIVE on the Cap-7 plane (region label, sticky mesh node and factory land, land rotate among 7 sites), not a public egress IP, not a residential IP, and not AZVPN. The public MirageGrid Worker Cap-7 control plane is LIVE at https://miragegrid.vibelock.workers.dev/v1/egress and https://miragegrid.vibelock.workers.dev/v1/planned. AZVPN stays the suite VPN concentrator.
ForgeReceipts is not legal advice and does not contact courts.
ZionPattern Solver never claims more than 75% confidence. It does not solve cases.
VeilLock does not inject into FaceTime or any calling app. YOUR camera/screen only.
AZ-CLCE detects inconsistency, not intent. Type D is a label, not a finding of malice.
ChronoLock is advisory only — not a scheduler, not targeting, not virality. 08:30–10:30 local. Distinct from TemporalLock.
The ARK is not a kernel. Hosted API never unlocks or encrypts with a passphrase and never stores vaults. Sweep is Mode E heuristics only.
AZAI is a standalone local core with an OpenAI-compatible API, not a new foundation model and not an Ollama identity. Ollama is optional SLOT. Hosted / in-process
/v1is a protocol mirror + Lamb check (Service → Clarity → Peace), not a provider proxy. Jeeves is not sovereign.SpectralLock 0.3.1 hosted overlay is a 256px preview, not a spectrometer, not forensic. Wheel paint is a membership-tint plane separate from the spectral triad. Inject ON is paint, not pigment recovery. Restore lost pigment is LIVE on FragGate ops
pigmentandrestore-pigment(listPigment/pigmentFromB64) and refusesSL-PIGMENT-GONEwhen the faded signal is gone. AMOE is not a live product. Leftover-bytes recover is honest (present container bytes only); incremental PDF revision graphs + per-revision copies are honest; opaque refuse is honest; universal recover marks 7z / HEIC / HEIF SLOT; handwriting is a 256px PNG ink-scan heuristic (not ESDA / court cert; hosted JPEG SLOT); never OCR-from-black-box. Unredact / recover / handwriting stay on spectrallock-download-tracker (/v1/unredact,/v1/recover,/v1/handwriting) — not FragGate door ops. UV is not a lamp. Balance/lemon/indent never invent marks. Full pipeline is the Python package.EmployeeLock is not a court, not UL, not a truth score. Hosted never stores xlsx. Demo rows are format proof, not case facts.
FoldLock is not zip. Hosted / in-process preview is tether-suppression on small UTF-8 text. Ratios are receipts, not trophies. Short strings can grow.
WhistleLock is a local vault + dead-man copy. Not a mailer. Hosted never holds whistle files.
TrajectoryLock is a research prototype / auditable geometric test. Not a certified forensic instrument. Hosted never stores media. Match probability is P(match | declared model), not P(official account is true). Synthetic examples are not real-case findings.
M.I.A.Lock Doe hits are compatibility leads only — never an ID. Coverage heat is not presence. No live tracking.
Aziel Corpus Library is a public library index + counted PDF/package download. Not a private-file search engine, not Zenodo, not a new Lock engine.
AzielTether is not a VPN. Prefer-central mesh for downloaded Aziel Eliab software; public HTTPS stays mesh-free.
PeaceLock is chosen silence / chosen inaction as a first-class receipt (PL-WP-0.1). Not a transcript, not a counterfactual, not a motive score, not a HARD_DUTY waiver. Hosted never invents speech or stores files.
4DMap is a four-axis inspection frame T/Δ/Γ/Π (4DM-WP-1.0). Not a sequential gate, not a truth score, not a Lumen panel, and not an extra door (
domains_are_doors:false). Does not invent marks or backdate class. Inspection frame after AZPIPE. FragGate claims cite join types. ChainLock may stamp walks.AZBrowser is the Lamb Lens ethical research browser (AZB-1.0). Not Chromium, not a Tor exit, not an unrestricted proxy. Lamb Lens cites; refuses harmful harvest; never invents visit results. FragGate only. AZNet is separate software (same FragGate door) — pairing is order/token only, not a shared Phase-1 UI.
AZNet is a silent verification side-net (AZN-WP-0.1) on the Cap-7 and
.azielname plane. Separate product (own Workeraznet-download-tracker, own UI). Cap-7 / MirageGrid stay name and land-region metadata: not an ICANN registrar, not a public egress IP, and not AZVPN. The device-to-device packet plane is separate and NOT-READY. Failover order is LAN, Wi-Fi, Bluetooth, RF, then photon light flashes. Each carrier is FG-STUB until a real hop works. That path is not a live alternative internet. Not a payload host. Garden / stamp / memorial ops require AZBrowserpair_tokenANDpair_flag(functional order only). Hosted never stores payloads.
Product slugs → Workers
slug | Worker hostname | example ops | session exec |
vibelock | vibelock-download-tracker | analyze | in-process (features/PCM; no live mic) |
veillock | veillock-download-tracker | apps | in-process (no camera inject) |
codelock | codelock-download-tracker | render | in-process |
godlock | godlock-download-tracker | score, submit | in-process (not a VPN) |
shadowlock | shadowlock-download-tracker | observe | in-process (no OS hook) |
temporallock | temporallock-download-tracker | genesis, append, verify | in-process |
forgereceipts | forgereceipts-download-tracker | receipt | in-process (not legal advice) |
decisiongate | decisiongate-download-tracker | check | in-process |
zsolver | zsolver-download-tracker | patterns, score, session | in-process |
azos | azos-download-tracker | status | in-process (session/exec/lattice per-op proxy) |
glossafilter | glossafilter-download-tracker | render | in-process |
miragegrid | miragegrid-download-tracker | assign | in-process (control-plane assign + Cap-7 mesh-name metadata; factory is not a public ICANN registrar; not a hosted VPN hop; Cap-7 geo/sticky/rotate LIVE on the Cap-7 plane, not a public egress IP) |
staticclock | staticclock-download-tracker | advise | in-process |
chronolock | chronolock-download-tracker | advisory, anchors | in-process |
postking | postking-download-tracker | new, move, status | in-process |
azclce | azclce-download-tracker | score, classify, gate | in-process |
ark | ark-download-tracker | sweep, levels | in-process |
azai | azai-download-tracker | health, lamb-check | in-process (Lamb only; not the blend) |
spectrallock | spectrallock-download-tracker | health, modes, overlay | in-process (256px PNG preview; inject ON/OFF; leftover-bytes + revision-graph + recover/handwriting honesty; no unredact/recover/handwriting door) |
azbot | azbot-download-tracker | health, skill, route | in-process (skill router, not a model) |
employeelock | employeelock-download-tracker | health, append-preview, verify-canonical, skill | in-process (no xlsx store) |
foldlock | foldlock-download-tracker | health, fold-preview, unfold-preview, skill | in-process |
whistlelock | whistlelock-download-tracker | health, hash-preview, canon-preview, skill | in-process (no file store) |
trajectorylock | trajectorylock-download-tracker | health, example, analyze, skill | in-process (geometry; no media store) |
mialock | mialock-download-tracker | map, search-options, queries, doe-match, coverage | in-process (leads ≠ ID) |
azieltether | azieltether-download-tracker | health, skill, verify | in-process (not a VPN) |
peacelock | peacelock-download-tracker | open, seal, break, show, verify, stamp | in-process (HARD_DUTY refuse; ABSENT invariants) |
azmail | azmail-download-tracker | airlock_classify, scrub, trust_score, mesh_*, keyword_alert_* | in-process (FragGate only; mesh default off; not an MTA) |
azbrowser | azbrowser-download-tracker | ethical_search, lamb_lens_search, navigate, airlock_ingest, tab_*, receipt_list, verify | in-process (FragGate only; Lamb Lens; not Chromium) |
aznet | aznet-download-tracker | pair_status, garden_list, stamp, verify_hash, memorial_*, receipt_verify | in-process (FragGate only; never hosts payloads; AZBrowser pair required) |
azhub | azhub-download-tracker | region_list, place_module, remove_module, tether_*, blank_key_status | in-process (FragGate only; Blank Key; not AZInterface; no auto-unlock) |
azinterface | azinterface-download-tracker | genesis_status, site_state_*, integrity_check, witness_list, page_cycle_status | in-process (FragGate only; suite shell, package 0.1.0; pre-locked page cycles; local pipeline_arch / withdraw / scorch_local / pair_* stay off the public door) |
aziel-corpus | aziel-corpus-download-tracker (www.azielcorpuslibrary.net) | health, search, example, skill | in-process (sample MASTER; live D1/Whisper/OCR per-op proxy) |
4dmap | 4dmap-download-tracker | health, skill, pin, span, stack, gap, fork, walk, lens, class, cohort, absence, cap, join, list, example, card_new, card_pin, card_span, card_join, card_walk, card_list, verify_hash, frame_status, axis_describe, walk_trace, card_export, card_import, verify_chain, neighbor_cite, memory_cite, memory_observe, library_pin, plot, possibility, pattern_recall, lattice_tip, poison_refuse, news_status, news_pin, news_open, news_ingest, news_sources, news_weather, news_black_swan | in-process (4DM-WP-1.0 / 0.3.0; inspection frame after AZPIPE; not an extra door; not a sequential gate; AZNews is standalone via news_ingest and joined via news_pin / news_open; an empty pin refuses AZNEWS-SOURCE-ABSENT; the global live flag stays false) |
Catalog aliases (also accepted on /v1/pull/{slug}): az-clce → azclce,
zion-pattern-solver → zsolver, postking-chess → postking,
aziel-digital-library → aziel-corpus, mia-lock → mialock,
peace-lock → peacelock, az-mail / app-1.0 → azmail,
az-browser / lamb-lens → azbrowser,
az-net / azn-wp-0.1 → aznet,
az-hub / blank-key → azhub, az-interface / page-cycle → azinterface.
aznet is not an AZBrowser alias — AZNet is separate software (same FragGate door).
fourdmap / 4d-map / 4dm-wp-1.0 → 4dmap.
AZHub and AZInterface are sibling softwares under the same FragGate door (never aliases of each other).
Software hubs (corpus / godlock.uk / azieleliab) list catalog products[] after
merge: slug azhub / azinterface / aznet / azbrowser, workers
azhub-download-tracker / azinterface-download-tracker /
aznet-download-tracker / azbrowser-download-tracker, github
https://github.com/AzielEliab/azhub ·
https://github.com/AzielEliab/azinterface ·
https://github.com/AzielEliab/aznet ·
https://github.com/AzielEliab/azbrowser.
AZHub, AZInterface, AZNet, and AZBrowser are separate products (own Workers,
own UIs; never nested). Pairing AZNet with AZBrowser is functional order only.
FragGate itself is not a 34th true-engine product. Hubs already show its
GitHub; this runtime also publishes a catalog-friendly kernel card at
catalog.json extras[] / fraggate
(slug: "fraggate", kind: "kernel",
github: "https://github.com/AzielEliab/fraggate",
worker: "fraggate-download-tracker", engine: false).
FragGate is the kernel door; human UI + counted download is the separate
FragGate Worker app (not nested in AZBrowser, AZHub, or AZInterface):
https://fraggate-download-tracker.vibelock.workers.dev/
If a sibling /v1 API is not live yet, the proxy returns that Worker's response
(often 404 JSON) and the combined OpenAPI still lists the expected path.
GET /v1/pull/{slug}/skill falls back to a catalog-built skill so an AI can
still invoke.
Vendored engine artifacts live under src/engines/. engine_digest is SHA-256
of those file bytes (sorted path order). Recompute with
node scripts/hash-engines.mjs --write.
Deploy
npx wrangler deployAccount ac575a9b822bea2bed97d0ab73aed238. workers.dev
aziel-runtime.vibelock.workers.dev. Product download KV stays on each
product Worker. This runtime's USES namespace is the API use counter
and ring log (GET /v1/uses) — no Authorization, tokens, bodies, or PII.
Production KV ids in wrangler.toml: USES c1f89ba6f1db47328d36379cdd69b7ab,
AZMAIL_MESH ce81cecf8b75412fb7b56e1119e017da, AZBROWSER_TABS
7487aba1bbb5417fb668de86d8b48f37. Do not create replacement namespaces.
Same-origin doors (/runtime on azielcorpuslibrary.net, godlock.uk,
www.azieleliab.com) should set X-Aziel-Runtime-Via or
X-Aziel-Runtime-Host (origin, azieleliab.com, godlock.uk,
azielcorpuslibrary.net) so host counters stay distinct.
1.2.0+ requires Durable Object migration tag v1 (RuntimeSession, SQLite).
The first deploy after the session cut creates the SESSION binding. 1.4.0
does not need a new DO migration — engines run in the same isolate. 1.4.1
reuses that SESSION class. 1.5.0, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 1.6.9, 1.6.10, 1.6.11, 1.6.12, 1.6.13, 1.6.14, 1.6.15, and 1.7.0 do not need a new DO migration.
Optional production token (session mutate only — catalog / health / runtime / skill / pull stay public):
# wrangler.toml
# [vars]
# REQUIRE_TOKEN = "1"npx wrangler secret put RUNTIME_TOKEN
npx wrangler deploy
node scripts/probe-live.mjsIf RUNTIME_TOKEN is unset and REQUIRE_TOKEN is not 1, sessions stay open
(dev). If the secret is set, POST /v1/session/open|policy|exec|close requires
Authorization: Bearer … or X-Aziel-Runtime-Token. GET /v1/ready is 200
only when the SESSION Durable Object binding is up, and 503 when
REQUIRE_TOKEN=1 and the secret is missing. Authority JSON (/v1/health,
/v1/ready, /v1/runtime.json, /v1/catalog.json) is Cache-Control: no-store.
Receipts cap at 64. Sessions expire after 6h. Per-IP: 20 opens / minute, 60
execs / minute (HTTP 429 JSON).
Push to main runs .github/workflows/deploy.yml (npx wrangler deploy --keep-vars --var GIT_SHA:<sha>) only
when repo secret CLOUDFLARE_API_TOKEN is set. Missing token skips the job
(does not fail). --keep-vars leaves existing Worker vars in place. Primary deploy is Cursor/wrangler OAuth (Aziel Eliab).
Account ac575a9b822bea2bed97d0ab73aed238 is the non-secret default. Do not
put tokens in the repo. workflow_dispatch is also enabled. The Action passes
GIT_SHA so /v1/software can stamp git_sha.
/llms.txt version_id is the Cloudflare Worker version id from the
CF_VERSION_METADATA binding (wrangler.toml [version_metadata]), read when
the response is served. It is not a UUID stored in this repo. An isolate
without that binding, and without VERSION_ID, publishes version_id: null.
Box deploy (OAuth wrangler, no API token in the environment):
env -u CLOUDFLARE_API_TOKEN npx wrangler deploy --keep-vars --var GIT_SHA:$(git rev-parse HEAD)Add --var VERSION_ID:<worker-version-id> only when that id is already known.
Do not invent one. When the binding is present it wins over VERSION_ID.
If this checkout has no wrangler credentials, deploy from the author's machine.
Pass GIT_SHA. Omitting it leaves the catalog on deploy lag and does not claim git HEAD:
npx wrangler secret put RUNTIME_TOKEN
npx wrangler deploy --keep-vars --var GIT_SHA:$(git rev-parse HEAD)
node scripts/probe-live.mjs
# confirm GET /v1/health and /v1/ready and /v1/runtime.json version=1.7.0 role=engine-runtime door=fraggate
# confirm GET /v1/uses returns uses / by_host / by_path / by_day / recent (no increment)
# confirm engine_slugs == true_engine_slugs == all 36 catalog slugs
# confirm POST /v1/session/open → policy → exec each primary op → receipt has engine_digest + ran_inLibrary /runtime mirror
https://www.azielcorpuslibrary.net/runtime is the Aziel Digital Library reverse-proxy / mirror of this Worker. Primary public host / discovery is Try on Glama. The corpus Worker advertises and reverse-proxies:
GET https://www.azielcorpuslibrary.net/runtime— library mirrorGET https://www.azielcorpuslibrary.net/runtime/v1/skill→ this/v1/skillGET https://www.azielcorpuslibrary.net/runtime/v1/runtime.json→ this/v1/runtime.jsonGET https://www.azielcorpuslibrary.net/runtime/v1/software→ this/v1/softwareGET https://www.azielcorpuslibrary.net/runtime/v1/update/check?slug={slug}&version={installed}→ this/v1/update/check?slug={slug}&version={installed}(slug required)GET https://www.azielcorpuslibrary.net/runtime/v1/bundle→ this/v1/bundleGET https://www.azielcorpuslibrary.net/runtime/v1/pull/{slug}→ this/v1/pull/{slug}POST https://www.azielcorpuslibrary.net/runtime/v1/session/open→ this session objectGET https://www.azielcorpuslibrary.net/runtime/v1/uses→ this/v1/uses(setX-Aziel-Runtime-Via: azielcorpuslibrary.net)POST https://www.azielcorpuslibrary.net/runtime/v1/fraggate/call→ this FragGate door (AZMail and every live slug; no side door)
See the companion PR on AzielEliab/aziel-corpus.
Network security claims (AZP-NS-1.0)
The protocol modules under src/security/, src/transport/, src/checkpoints/, and src/replication/ are specified in docs/designs/AZP-NS-1.0.md.
Records are tamper-evident: hash-linked and signed. Independent replication is fixture-tested. This is not a claim of immutability.
Payloads are privacy-preserving: encrypted end to end, with node identity separated from session identity. This is not anonymity.
Checkpoints are survivable and federated in the fixture model. This is not an unkillable network.
Relays are untrusted transport. They cannot decrypt payloads. That design rule is not a production zero-trust certification.
Cap-7 is not public ICANN and is not a public egress IP. Mirage is not AZVPN. aznet_replaces_internet is false. Tor, UDP, radio, and sandbox bearers are refused and are not LIVE. Softwares stay 42. tools/list stays 36. Live multi-provider recovery and Plane B Framagit are operator work, not a result of these scripts.
License
Apache License 2.0. Copyright 2026 Aziel Eliab.
Available Tools
36 toolschainlock_appendChainLock appendAInspect
Append one fact-bearing stamp to a local ChainLock chain (CL-WP-0.4). Grounded write — not a tip read, not AKM observe, not a LOCKSET seal. Fabric, not Softwares-tab. No Node Gate. Use this when you have a concrete fact to stamp onto a named chain. Do not use it for reading the tip, adaptive memory observation, or sealing LOCKSET; use chainlock_tip, memory_observe, or chainlock_seal instead. Write: additive append (append-only vault; no chainlock_delete). Hash-only or empty fact refuses no-fact. Unknown roster name refuses unknown-chain. Oversized card refuses card-cap. Does not write godlock.uk. Omit c/chain to stamp the session chain. Door aliases: chain→c, s→subject, f→fact, kind→k. Omit k to store kind stamp. subject clips to 80; fact clips to 160 then refuses if still empty. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns the new stamp (id, h, fh, chain, seq) plus display envelope.
| Name | Required | Description | Default |
|---|---|---|---|
| c | No | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to stamp the session chain. | |
| k | No | Optional kind label. Omit to store kind stamp. Alias: kind. | |
| fact | Yes | Required fact text clipped to 160 characters. Empty or hash-only after clip refuses no-fact. Alias: f. | |
| chain | No | Alias of c. Omit both to stamp the session chain. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| subject | No | Optional subject clipped to 80 characters. Alias: s. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Append body: ok, stamp (id, c, k, fact, fh, stamp_sha256, prev), card, seq, vault path. Refuses: no-fact, unknown-chain, card-cap. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Despite annotations providing minimal hints, the description thoroughly discloses behavior: append-only (no chainlock_delete), refusal conditions (no-fact, unknown chain, card-cap), the godlock.uk exclusion, the confirm/dry_run gate, and the distinction between consent and tenant auth. This goes far beyond the annotation fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but every sentence earns its place. It front-loads the core action, then exclusions, then behavioral rules, then parameter details and output summary. No filler; the structure guides an agent from decision to invocation.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutation tool with a runtime gate, aliases, multiple refusal conditions, and a specific output shape, the description covers everything needed: when to call, how to call, what can go wrong, and what is returned. The output schema exists, but the description still explains the return envelope, making it self-sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description adds substantial meaning: alias mappings (chain→c, s→subject, f→fact, kind→k), the clipping behavior with empty-after-clip refusal, the precise semantics of confirm as consent (not auth) and dry_run as a preview that still runs safety checks. These details are not fully captured in the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource: 'Append one fact-bearing stamp to a local ChainLock chain'. It then distinguishes itself from three siblings (chainlock_tip, memory_observe, chainlock_seal) and names the exact conditions for use, making its purpose unmistakable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when to use ('when you have a concrete fact to stamp onto a named chain') and when not to ('Do not use it for reading the tip, adaptive memory observation, or sealing LOCKSET'), naming the alternatives. Also covers the session-chain default ('Omit c/chain to stamp the session chain').
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chainlock_recallChainLock recallARead-onlyIdempotentInspect
Grounded ChainLock recall at depth 0–5 (id+h+fh facts or refuse=no-stamp). Stamped vault facts — not Bayesian rank and not tip-only. Use this when you need stamped facts from the local vault, not a Bayesian ranking. Do not use it for adaptive memory ranking or reading only the live tip; use memory_recall or chainlock_tip instead. Depth above 5 is clipped to 5. refuse=no-stamp when empty — do not invent a fact. Append-only; there is no chainlock_delete. Omit depth to use 1 (not 0). 0 = tip only; 5 = full chain / genesis budget. Omit c/chain to scan session+acts+recall+learn (not the whole roster). q/query is a case-insensitive subject/fact substring; empty q does not invent cards. Returns grounded facts (id, h, fh) or refuse=no-stamp.
| Name | Required | Description | Default |
|---|---|---|---|
| c | No | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to scan session, acts, recall, and learn — not the full roster. | |
| q | No | Optional case-insensitive substring over subject/fact. Alias: query. Empty does not invent matches. | |
| chain | No | Alias of c. Omit both to scan session, acts, recall, and learn — not the full roster. | |
| depth | No | Optional recall depth. Omit for 1. 0 = tip only; 5 = genesis/budget maximum. Values outside 0–5 are clipped. Alias: d. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark readOnlyHint=true, idempotentHint=true, destructiveHint=false, and the description adds substantial behavioral detail: depth clipping above 5, default depth of 1, default chain set, refuse=no-stamp when empty, no fact invention, and append-only/no-delete semantics. This goes well beyond the structured annotations and does not contradict them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense and front-loaded, with the core purpose and exclusions near the beginning. It is somewhat longer than strictly necessary and repeats a couple of schema defaults (e.g., default chains), but every clause carries operational value and the structure is logical.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only recall tool with a rich output schema, the description is complete: it defines scope, defaults, edge behavior, alternatives, and return shape. An agent has everything needed to decide when to call it and what to expect.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but the description adds meaning not in the schema: depth values map to behavior ('0 = tip only; 5 = full chain / genesis budget'), out-of-range values are clipped, omitted c/chain scans a specific subset, and q is a case-insensitive substring with empty-q behavior. This significantly enhances the schema's parameter documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource ('Grounded ChainLock recall at depth 0–5') and specifies output shape ('id+h+fh facts or refuse=no-stamp'). It explicitly contrasts with 'Bayesian rank' and 'tip-only', differentiating it from siblings like memory_recall and chainlock_tip.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It states exact use conditions ('Use this when you need stamped facts from the local vault') and exclusions ('Do not use it for adaptive memory ranking or reading only the live tip'), naming memory_recall and chainlock_tip as alternatives. It also clarifies defaults for depth and chains, leaving no ambiguity about invocation context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chainlock_sealLOCKSET sealAInspect
Write a new local LOCKSET over live chain tips (members {c,id,h,fh} + TemporalLock + GodLock cite, LS-WP-0.1). Not a raw-session close and not verify-only. Use this when the operator wants a new local lockset over current tips. Do not use it for verify-only, appending one fact, writing godlock.uk, or sealing a raw runtime session; use chainlock_verify, chainlock_append, or runtime_session_close instead. Write: replaces receipts/LOCKSET.json. Empty vault (no live tip on any roster chain) refuses empty-vault. Empty chains are omitted from members, not invented. Runtime cites godlock.uk and does not write the public ledger — the operator posts lockset_sha256. A later seal overwrites the previous local lockset. Empty {} still attempts the seal. Omit ts so TemporalLock stamps now. Passing ts labels that receipt only and never backdates seal authority or prior stamps. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns lockset document (members, temporal, godlock cite) and lockset_sha256.
| Name | Required | Description | Default |
|---|---|---|---|
| ts | No | Optional ISO-8601 timestamp copied onto the TemporalLock block. Omit to use now. Never backdates authority, prior stamps, or godlock.uk. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Seal body: ok, lockset (members, temporal, godlock, lockset_sha256), or refuse empty-vault when no live tips exist. Does not write godlock.uk. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description richly discloses side effects and edge cases: it 'replaces receipts/LOCKSET.json', a later seal overwrites the previous lockset, empty-vault refuses, empty chains are omitted, runtime does not write the public ledger, and dry_run still returns FragGate refuse codes. This goes well beyond the annotations, which only provide broad boolean hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with purpose and sibling routing, then systematically covers mutation requirements, edge cases, and return values. It is long but dense; minor redundancy exists because confirm/dry_run/ts semantics are repeated from the input schema descriptions.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutation tool with no required parameters, the description covers mutation preconditions, refusal paths, overwrite behavior, timestamp limitations, dry-run semantics, and the return value. The output schema supplies the return shape, so nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description mostly restates the ts, confirm, and dry_run semantics already present in the input schema, though it adds useful context such as 'Empty {} still attempts the seal' and the relationship between confirm and runtime consent.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Write a new local LOCKSET over live chain tips' and specifies the exact member fields. It also explicitly distinguishes itself from siblings by naming chainlock_verify, chainlock_append, and runtime_session_close and stating what it is not.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The tool states exactly when to use it: 'Use this when the operator wants a new local lockset over current tips.' It also gives explicit exclusions and alternatives: 'Do not use it for verify-only, appending one fact, writing godlock.uk, or sealing a raw runtime session; use chainlock_verify, chainlock_append, or runtime_session_close instead.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chainlock_tipChainLock tipARead-onlyIdempotentInspect
Read only the live tip card of one local ChainLock chain — not depth recall and not LOCKSET verify. Use this when you need the current tip of a named chain. Do not use it for depth-0–5 grounded recall, LOCKSET verify, or adaptive memory explain; use chainlock_recall, chainlock_verify, or memory_get instead. Does not invent a missing tip. An empty chain returns ok with tip=null and empty=true (not a refuse). Fabric module — not a Softwares-tab product. Omit c/chain to read the session chain tip (not the full vault). chain is an alias of c. This is one card, not depth recall. Returns the tip card (id, h, fh) or tip=null / empty=true when that chain has no stamp.
| Name | Required | Description | Default |
|---|---|---|---|
| c | No | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to read the session chain tip. | |
| chain | No | Alias of c. Omit both to read the session chain tip. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Tip body: ok, chain, tip card or null, empty flag, seq when a stamp exists. Empty chain is ok+empty, not an invented card. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already carry the safety profile (readOnlyHint=true, idempotentHint=true, destructiveHint=false), so the bar is lower. The description adds genuine value beyond them: it discloses the empty-chain behavior (returns ok with tip=null and empty=true, not a refuse) and the open-world stance ('Does not invent a missing tip'). This is meaningful behavioral context annotations do not convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The core purpose is front-loaded in the first sentence, and almost every sentence earns its place (usage boundaries, empty-chain semantics, module scoping, default behavior, alias). Slight redundancy: 'This is one card, not depth recall' restates the opening's 'not depth recall', which trims the conciseness score.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a low-complexity tool (0 required params, enums for both) with an output schema, annotations, and full schema coverage, the description covers all residual gaps: usage boundaries, default behavior, empty-chain edge case, and return shape. An agent has everything needed to call it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with both parameters fully described including enums, alias relationships, and the omit-to-read-session-chain default, so the schema does the heavy lifting. The description adds only marginal nuance ('not the full vault') beyond what the schema already states; baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource+scope: 'Read only the live tip card of one local ChainLock chain'. It explicitly differentiates from siblings with 'not depth recall and not LOCKSET verify' and later 'This is one card, not depth recall', so an agent can distinguish it from chainlock_recall and chainlock_verify without opening their schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicit when-to-use ('Use this when you need the current tip of a named chain') and when-not-to-use with named alternatives ('Do not use it for depth-0–5 grounded recall, LOCKSET verify, or adaptive memory explain; use chainlock_recall, chainlock_verify, or memory_get instead'). Nothing is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chainlock_verifyChainLock / LOCKSET verifyARead-onlyIdempotentInspect
Confirm fail-closed integrity of ChainLock chains and LOCKSET (LS-WP-0.1): broken prev, tip drift, missing GodLock cite. Integrity check — not a new seal. Use this when you must prove local chain integrity before trusting a recall. Do not use it for appending a stamp or sealing a new lockset; use chainlock_append or chainlock_seal instead. Cites godlock.uk; does not write the public ledger. Fail-closed — do not repair silently. Break reasons include broken-prev, stamp-hash-miss, body-hash-miss, tip-drift, missing-godlock-cite. Omit c/chain to verify every roster chain plus the stored LOCKSET. require_seal=true fails closed if no lockset is stored. Returns chain_ok, LOCKSET lattice, and per-chain verify notes.
| Name | Required | Description | Default |
|---|---|---|---|
| c | No | Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to verify every roster chain plus the stored LOCKSET. | |
| chain | No | Alias of c. Omit both to verify every roster chain plus the stored LOCKSET. | |
| require_seal | No | Optional. When true, fail-closed if receipts/LOCKSET.json is missing. When omitted, a stored lockset is still checked if present. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, so the safety profile is covered. The description adds valuable behavioral context beyond annotations: it is fail-closed, does not write the public ledger, does not repair silently, and lists concrete break reasons. It also clarifies that require_seal=true fails closed when no lockset is stored. This is meaningful added context, though it does not detail the exact return shape (output schema exists).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but every sentence earns its place: purpose, usage boundary, side-effect disclosure, fail-closed behavior, break reasons, parameter semantics, and return summary. It is front-loaded with the core purpose and scoping, and the alternative-tool routing appears early. No filler or repetition of schema content.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only verification tool with an output schema, the description covers the invocation context, the fail-closed contract, the break reasons, the alias behavior, and the require_seal edge case. The output schema handles return-value details, so nothing an agent needs to call this correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all three parameters. The description adds value by explaining the semantic effect of omitting c/chain ('verify every roster chain plus the stored LOCKSET') and the fail-closed meaning of require_seal=true. It also clarifies that c and chain are aliases. This goes beyond the schema's field-level descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Confirm fail-closed integrity'), a specific resource ('ChainLock chains and LOCKSET'), and explicitly distinguishes itself from appending or sealing. It names the sibling tools it is not (chainlock_append, chainlock_seal), so an agent can select it correctly without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use ('when you must prove local chain integrity before trusting a recall') and when-not-to-use ('Do not use it for appending a stamp or sealing a new lockset'), naming the alternatives. It also explains the omit-c/chain behavior and require_seal=true semantics, leaving no ambiguity about invocation context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
decisiongate_checkRun DecisionGATE on a proposalAInspect
Run the named DecisionGATE five sequential gates on a proposal (Freedom without clarity is chaos) without executing a catalog product. Also runs automatically inside fraggate_call before exec. Use this when you want a gate check without executing a catalog product verb. Do not use it for executing a product op or searching the library; use fraggate_call or library_lookup instead. Write: appends an ask/refuse ledger tip (not idempotent). Empty {} still runs the five gates and stamps the ledger. Does not execute domain software. Named wrapper — same DecisionGATE kernel; not the full MASTER-33 hop list; Softwares exec stays fraggate_call. All proposal fields are optional. Missing evidence can fail a gate. accountable identity on this runtime is Aziel Eliab only. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns gate view, final_state, ledger_tip, and result (code FG-OK on the named module wrapper).
| Name | Required | Description | Default |
|---|---|---|---|
| values | No | Optional values list. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| evidence | No | Optional evidence strings. Missing evidence can fail a gate. | |
| statement | No | Optional proposal statement to evaluate. | |
| impact_neg | No | Optional negative-impact list. | |
| impact_pos | No | Optional positive-impact list. | |
| accountable | No | Optional accountable party string. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses that the tool writes to the ledger ('appends an ask/refuse ledger tip (not idempotent)'), requires confirm=true for mutation, and explains dry_run behavior including returning refusal codes. It also mentions it does not execute domain software and notes the accountable identity. This goes well beyond the sparse annotations (readOnlyHint=false, idempotentHint=false) by providing operational context and side-effect details.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but dense with essential information. It front-loads the core action and usage, then covers side effects and parameter nuances. While it could be split into sections, it avoids redundancy with the schema and every clause adds useful detail.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers the full calling context: purpose, usage, side effects, confirmation requirements, dry_run behavior, identity, and return values (gate view, final_state, ledger_tip, result). It even addresses edge cases like empty {} and optional fields. Given the output schema exists, this is comprehensive for an agent to correctly invoke the tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with detailed parameter descriptions. The description adds extra meaning by noting that 'Missing evidence can fail a gate' and 'All proposal fields are optional,' which is not obvious from individual parameter descriptions. It also clarifies the confirm/dry_run semantics in context. This adds value beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool runs the five DecisionGATE gates on a proposal without executing a catalog product. It explicitly differentiates from siblings by saying 'Do not use it for executing a product op or searching the library; use fraggate_call or library_lookup instead.' The verb 'run' plus resource 'DecisionGATE five sequential gates' is specific.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides explicit when-to-use guidance: 'Use this when you want a gate check without executing a catalog product verb.' It also gives clear exclusions and alternatives, naming fraggate_call and library_lookup. Additionally, it notes the tool runs automatically inside fraggate_call before exec, which helps an agent decide whether to call it directly.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fraggate_callStep 3 — Call the picked slug through FragGateAInspect
Execute the slug you picked from Softwares through the FragGate single door (CallEnvelope → FragGate → Lamb Lens → SweepGate → Sentinel → Provenance → ChainLock-IN → DecisionGATE → AZPIPE → Internal Domain Layer → optional ASE → RoseClock → TemporalLock → ChainLock-OUT → ForgeReceipts → Return). Default exec path — not the catalog and not a raw session. Use this when Softwares already returned a slug and a live allowlisted op is known. Do not use it for picking the catalog slug, searching library papers, or raw session plumbing; use Softwares, library_lookup, or (only if asked) runtime_run / runtime_session_exec instead. Side effects are operation-dependent (read, write, or refuse). May reach an open world when the target op does (for example AZBrowser ethical_search); many ops stay isolate-local. Unknown names refuse FG-HALLUC-TOOL. Stub, local-only, and Remain-OFF verbs refuse FG-STUB / FG-LOCAL-ONLY / FG-GATE-REFUSE / FG-LAMB-REFUSE. FragGate is THE single door. Required: op, unless job_id is set (that reads a background job and does not start another). Also pass slug or name. Shorthand name foldlock/fold-preview is accepted. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id/confirm/dry_run/background/job_id become the op payload when payload is omitted. Example preview: {"name":"foldlock/fold-preview","payload":{"text":"the cat and the dog"},"dry_run":true}. Optional background=true returns Running and a job_id before the op finishes; Done only after a receipt hash exists. Poll with the same job_id and confirm=true. dry_run does not start a job. UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, doctor, pair) forward to catalog ops. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns status, result, receipt, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, and limitations. Not the full FragGate door. Empty fraggate_list is discovery (hashed LIVE_OPS). Catalog LIVE_OPS slugs (40): 4dmap, ark, azai, azbot, azbrowser, azchat, azclce, azcoherence, azhub, aziel-corpus, azieltether, azinterface, azmail, aznet, azos, azvpn, chronolock, codelock, decisiongate, embryolock, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, mmconsensus, peacelock, postking, shadowlock, spectrallock, staticclock, temporallock, toolbench, trajectorylock, vibelock, whistlelock, zkattest, zsolver. Compact product-verify tokens (not a second allowlist): allowlist.azhub LIVE_OPS: health, skill, region_list, place_module, remove_module, tether_declare, tether_cut, tether_list, blank_key_status, list_modules, place. allowlist.azinterface LIVE_OPS: health, skill, genesis_status, site_state_get, site_state_set, integrity_check, witness_list, page_cycle_status, mesh_radios, genesis_boot, hold. allowlist.azbrowser LIVE_OPS: ethical_search, lamb_lens_search, navigate, airlock_ingest, airlock, home, tab_open, tab_list, receipt_list, verify, receipt_verify, sandbox_status, sandbox_render, health, skill, vpn. allowlist.azvpn LIVE_OPS: health, skill, doctor, limitation, describe, open, status, list, close, send, recv, pull, peers, attach. allowlist.aznet LIVE_OPS: health, doctor, pair_status, pair, garden_list, stamp, verify_hash, memorial_list, memorial_append, receipt_verify, name_claim, name_read, name_resolve, slot_read, witness, witness_read, skill. UI aliases forward to catalog ops. EmbryoLock LIVE_OPS health/skill/doctor/verify-hash/policy/limitation; wipe/scorch/unlock stay FG-STUB on the public mesh.
| Name | Required | Description | Default |
|---|---|---|---|
| op | Yes | Required public allowlisted op from fraggate_describe (for example fold-preview, ethical_search, blank_key_status). UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, doctor, pair) forward to catalog ops. Unknown ops refuse FG-UNKNOWN-OP; stubs refuse FG-STUB. | |
| name | No | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL. | |
| slug | No | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. | |
| claim | No | Optional DecisionGATE proposal attached to this call. Also runs automatically inside the door even when omitted (defaults). Freedom without clarity is chaos. | |
| job_id | No | Optional job id from a background call (job_ + 16 hex). When set, the call reads that job and does not start another. confirm=true is still required. It does not re-run the op. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| payload | No | Optional op payload object. Shape is engine-specific (see fraggate_describe). Malformed fields are refused by the engine, not by this door schema. If omitted, leftover top-level keys are used as the payload. | |
| attempt_n | No | Optional 1-based attempt number for this call. Omitted means attempt 1 of a new request_id. | |
| background | No | Optional. When true, FragGate admits the call and returns Running with a job_id before the op finishes. Done is returned only after a receipt hash exists. dry_run does not start a job. A missing job is Quiet, not Done. | |
| request_id | No | Optional logical request id. The same value groups retries of one action on the ResultEnvelope and, for ForgeReceipts, inside the receipt hash. | |
| correlation_id | No | Optional client correlation id. Sealed inside a ForgeReceipts hash when this call mints one. | |
| parent_receipt_id | No | Optional prior attempt receipt hash. Null on the first attempt. This is not FragGate ledger prev, which stays call order only. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only cover the coarse safety profile (not read-only, open-world, non-idempotent, non-destructive); the description adds substantial behavior beyond that: operation-dependent side effects, specific refusal codes (FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY), that dry_run still runs allowlist/hallucination/stub checks, and that confirm is consent not tenant auth. This is meaningful disclosure the annotations cannot express.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose and usage are front-loaded, which is good, but the body is heavily bloated with enumerations of all 40 catalog slugs, per-product allowlist op lists, and repetition of confirm/dry_run caveats. Much of this belongs in fraggate_list/fraggate_describe rather than the call tool's own description.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a complex 13-parameter mutating tool with a nested claim object and an output schema, the description covers required-vs-alternative params, refusal codes, async behavior, and mutation gating adequately. Return fields are listed but the output schema exists, so that is not a gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds real semantics beyond the schema: leftover top-level keys become the payload when payload is omitted, shorthand foldlock/fold-preview name/op folding, job_id polling with confirm=true, and background job lifecycle. Its main defect is hedging ('Not the full FragGate door') rather than parameter meaning.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Execute the slug you picked from Softwares through the FragGate single door') and immediately scopes it as the default exec path, explicitly not the catalog and not a raw session. An agent can differentiate it from fraggate_list, fraggate_describe, and runtime_session_exec without opening a schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit when-to-use condition ('when Softwares already returned a slug and a live allowlisted op is known') plus explicit when-not ('Do not use it for picking the catalog slug, searching library papers, or raw session plumbing') with named alternatives (Softwares, library_lookup, runtime_run/runtime_session_exec). This is textbook routing guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fraggate_describeStep 2 — Describe the slug you pickedARead-onlyIdempotentInspect
Inspect one FragGate card for the slug you picked from Softwares (live vs stub vs local_only, public ops, engine_digest). Not execute and not a digest-only proof. Use this when you already have a name or slug from Softwares, fraggate_list, or GET /v1/software. Do not use it for discovering the full registry, proving a digest, pulling a hub product card, or executing an op; use fraggate_list, fraggate_verify, runtime_pull, or fraggate_call instead. Missing both name and slug, or an unknown name, refuses FG-HALLUC-TOOL. Wipe/unlock on embryolock stay FG-STUB. AZChat is LIVE+bound (mesh default off; not AZMail). Pass name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted. Returns one registry card (ops, stub_ops, digest, status, aliases).
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL. | |
| slug | No | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive, closed-world, so the safety profile is covered. The description adds real behavioral context beyond them: failure mode (missing name and slug, or unknown name, refuses FG-HALLUC-TOOL), stub/live status semantics, and a note that it is 'not execute and not a digest-only proof'. It stops short of describing response shape, but an output schema exists so that is not required.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Dense and front-loaded: the purpose and the not-this routing come first, then edge cases, then the return. It is longer than most descriptions and repeats the sibling list, but each clause carries operational information (error codes, live/stub, accepted forms).
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given a low-complexity 2-param read tool with full annotations and an output schema, the description covers purpose, routing, failure modes, and status semantics. What remains (exact card fields) is covered by the output schema, so the definition is complete enough to call correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and the schema already documents that one of name/slug suffices, the combined name/op form, and the FG-HALLUC-TOOL refusal. The description's param remarks largely restate that ('Pass name or slug — one is enough'), so it adds little beyond the structured fields; baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (inspect/describe) and resource (one FragGate registry card) plus the scope ('for the slug you picked'), and explicitly distinguishes itself from fraggate_list, fraggate_verify, runtime_pull, and fraggate_call. An agent can pick this tool over its siblings without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit when-to-use trigger ('when you already have a name or slug from Softwares, fraggate_list, or GET /v1/software') and an explicit when-not list mapped to named alternatives. Nothing is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fraggate_listStep 1 — List the FragGate registryARead-onlyIdempotentInspect
List hashed FragGate names and digests after Softwares so you can discover names. Discovery first — not the Softwares catalog and not exec. Use this when Softwares already returned a slug and you need live, stub, local_only, or digest status. Do not use it for the first catalog read, inspecting one known card, or executing an op; use Softwares (GET /v1/software), fraggate_describe, or fraggate_call instead. Empty {} only. Never enables mesh radios. Never invents tools or ops. Compact LIVE_OPS tokens below are discovery hints required by product verify scripts — they are not exec. Call fraggate_describe for the live card; later unknown names refuse FG-HALLUC-TOOL. Returns registry entries, allowlists, digests, and the MASTER-33 pipeline cite. Not the full FragGate door. Empty fraggate_list is discovery (hashed LIVE_OPS). Catalog LIVE_OPS slugs (40): 4dmap, ark, azai, azbot, azbrowser, azchat, azclce, azcoherence, azhub, aziel-corpus, azieltether, azinterface, azmail, aznet, azos, azvpn, chronolock, codelock, decisiongate, embryolock, employeelock, foldlock, forgereceipts, glossafilter, godlock, mialock, miragegrid, mmconsensus, peacelock, postking, shadowlock, spectrallock, staticclock, temporallock, toolbench, trajectorylock, vibelock, whistlelock, zkattest, zsolver. Compact product-verify tokens (not a second allowlist): allowlist.azhub LIVE_OPS: health, skill, region_list, place_module, remove_module, tether_declare, tether_cut, tether_list, blank_key_status, list_modules, place. allowlist.azinterface LIVE_OPS: health, skill, genesis_status, site_state_get, site_state_set, integrity_check, witness_list, page_cycle_status, mesh_radios, genesis_boot, hold. allowlist.azbrowser LIVE_OPS: ethical_search, lamb_lens_search, navigate, airlock_ingest, airlock, home, tab_open, tab_list, receipt_list, verify, receipt_verify, sandbox_status, sandbox_render, health, skill, vpn. allowlist.azvpn LIVE_OPS: health, skill, doctor, limitation, describe, open, status, list, close, send, recv, pull, peers, attach. allowlist.aznet LIVE_OPS: health, doctor, pair_status, pair, garden_list, stamp, verify_hash, memorial_list, memorial_append, receipt_verify, name_claim, name_read, name_resolve, slot_read, witness, witness_read, skill. UI aliases forward to catalog ops. EmbryoLock LIVE_OPS health/skill/doctor/verify-hash/policy/limitation; wipe/scorch/unlock stay FG-STUB on the public mesh.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish readOnly, idempotent, non-destructive, and closed-world. The description adds real value beyond that: it accepts only '{}', it never enables mesh radios, and it never invents tools/ops — a meaningful side-effect guarantee. It also sketches the payload (registry entries, allowlists, digests, MASTER-33 cite), though an output schema already exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The first four sentences are tight and front-loaded, but they are then buried under hundreds of tokens of LIVE_OPS slug dumps presented as 'discovery hints required by product verify scripts'. That bulk does not help an agent decide or invoke anything and repeats data the registry itself returns at call time.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
All essentials are present: no-arg contract, safety profile, routing to the three sibling tools, and an output schema to cover return values. What is missing is any hint about the shape/volume of the registry listing or pagination, and the token dumps add noise without filling a genuine gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters, so the baseline is 4. The description correctly reinforces the schema's 'send {}' contract with 'Empty {} only', and does not invent phantom arguments. No additional semantic depth is possible for a no-arg tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('List hashed FragGate names and digests') and immediately scopes it against the siblings that are NOT it — Softwares, fraggate_describe, fraggate_call. An agent can route correctly without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit precondition ('when Softwares already returned a slug and you need live, stub, local_only, or digest status') and an explicit exclusion list ('not the first catalog read, inspecting one known card, or executing an op'), each paired with the named alternative tool. This is a textbook when/when-not/alternative routing block.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fraggate_verifyVerify a registry name or digestARead-onlyIdempotentInspect
Confirm a name, slug, or 64-hex engine_digest against the hashed FragGate registry — a proof, not a card listing. Use this when you must prove a listed name or digest exists after fraggate_describe. Do not use it for listing the registry, describing ops, or executing; use fraggate_list, fraggate_describe, or fraggate_call instead. Not an exec path and not a describe card. Empty {} (no name, slug, or digest) refuses FG-HALLUC-TOOL. Digest without name/slug compares the whole registry hash (kind=registry). Name or slug with an optional digest compares that entry (kind=entry); unknown names refuse FG-HALLUC-TOOL. Mismatch returns ok=false with matched=false — it does not invent a digest. Send digest alone to proof the live registry_digest. Send name or slug (one is enough) to proof one card. Combined name+digest must equal that card's engine_digest. Returns match or mismatch (kind registry|entry, matched, registry_digest).
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL. | |
| slug | No | Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software. | |
| digest | No | Optional 64-char lowercase hex engine_digest or registry digest to verify. When digest is set without name/slug, the tool compares the live registry digest. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint. The description adds rich behavior beyond that: refusal for empty {} and unknown names (FG-HALLUC-TOOL), mismatch returning ok=false with matched=false, and the explicit statement that it does not invent a digest. These are material edge-case disclosures an agent needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but dense with necessary distinctions (registry vs entry, match vs mismatch). It is front-loaded with purpose and scoping, then covers edge cases. No filler sentences, though it could be tightened slightly without losing content. Given the complexity, this is appropriate.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has three distinct usage modes (digest-only, name/slug, combined) and an output schema; the description covers all combinations, refusal conditions, and the mismatch contract. Nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema descriptions cover all three parameters (100%), so the baseline is 3. The description adds cross-parameter semantics: digest-only compares the registry hash, name/slug compares an entry, and combined name+digest must match the card's engine_digest. This relational meaning goes beyond the schema's individual parameter notes.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Confirm') and resource ('name, slug, or 64-hex engine_digest against the hashed FragGate registry') and explicitly positions it as a proof rather than a listing. It names the sibling tools it is not (fraggate_list, fraggate_describe, fraggate_call), making differentiation unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides explicit when-to-use ('when you must prove a listed name or digest exists after fraggate_describe') and when-not-to-use ('Do not use it for listing the registry, describing ops, or executing') with named alternatives. The 'Not an exec path and not a describe card' sentence reinforces exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
library_lookupLibrary papers and citesARead-onlyIdempotentInspect
Search the Aziel Digital Library for papers and cites (aziel-corpus search, example, or skill) — cites, not beliefs and not vault stamps. Use this when you need a library paper, cite, example record, or library skill after Softwares and fraggate_call. Do not use it for running a Softwares slug, adaptive memory belief, ChainLock facts, or private-file search; use fraggate_call for a catalog slug, memory_recall, or chainlock_recall instead. Not a private-file search engine and not AKM/ChainLock. Empty q does not invent a cite. Unknown ops refuse FG-UNKNOWN-OP (allowed: search, example, skill, health). Named corpus wrapper — not MASTER-33; full aziel-corpus LIVE_OPS stay on fraggate_call. q is public corpus text — not memory_recall q and not ChainLock q. Omit op to search. Extra keys besides q/op/payload ride along as aziel-corpus payload (same as passing payload{}). Returns search, example, skill, or health payload inside the display envelope.
| Name | Required | Description | Default |
|---|---|---|---|
| q | No | Optional public-corpus query for op=search. Empty q returns an empty or default hit set, not an invented cite. Not a memory or ChainLock query. | |
| op | No | Optional library verb. search (default) looks up public corpus text; example returns a sample; skill returns the library skill; health is liveness. Other values refuse FG-UNKNOWN-OP. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, idempotent, non-destructive), and the description adds genuinely new behavior: unknown ops refuse with FG-UNKNOWN-OP, empty q does not invent a cite, and extra keys are forwarded as corpus payload. It stops short of describing pagination, result limits, or auth requirements, so not a full 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose and routing are front-loaded, which is good, but the description is a dense run-on that repeats the same exclusions twice ('not beliefs and not vault stamps' then 'not a private-file search engine and not AKM/ChainLock') and re-lists the op enum. Several clauses do not earn their place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be spelled out, and the description still notes the display-envelope wrapping. Routing, error behavior, and default op are all covered; only minor gaps like limits or auth context remain for this low-complexity, zero-required-param tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the schema already documents q, the op enum, the default, and the empty-q behavior, so the description is largely restating structured data. The only marginal addition is clarifying that extra keys ride along as payload — which the schema description already states. Baseline 3 is correct.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('Search the Aziel Digital Library for papers and cites') and immediately draws boundaries against siblings by declaring what it is NOT (beliefs, vault stamps, private-file search). An agent can distinguish it from fraggate_call, memory_recall, and chainlock_recall without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly names the triggering context ('when you need a library paper, cite, example record, or library skill after Softwares and fraggate_call') and enumerates the negative cases with the exact alternative to use for each ('use fraggate_call for a catalog slug, memory_recall, or chainlock_recall instead'). This is a full when/when-not/alternative routing table.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memory_calibrateCalibrate a memoryAInspect
Calibrate one memory with the deterministic 3-of-4 triad plus Bayesian posterior (AKM-TRIAD-1.0). Writes a LEARN stamp — not a ranked search and not an explain view. Use this when an observed memory should receive a posterior after evidence, not a ranked search. Do not use it for observing a new fact, resolving an outcome, or explaining a stored node; use memory_observe, memory_resolve, or memory_get instead. Write: forward-only RoseClock LEARN stamp. Posterior ≠ truth. authorizes_action=false. No automatic MODEL_UPDATE. subject or memory_id recommended. use_case labels calibration; it is not a permission. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns triad_score, omitted leg, posterior, effective N, and Brier notes.
| Name | Required | Description | Default |
|---|---|---|---|
| fact | No | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| subject | No | Optional subject key clipped to 80 characters. Used to find or create memory_id. | |
| use_case | No | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. | |
| memory_id | No | Optional existing memory id. Alternative to subject for resolve/calibrate/get. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Discloses that the tool writes a LEARN stamp, is a mutation requiring confirm/dry_run, has no automatic MODEL_UPDATE, and does not authorize actions. It also explains dry_run refusal-code behavior and that confirm is consent, not tenant auth. This goes well beyond the annotations, which are not contradicted.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with purpose and usage, then systematically covers behavior, parameters, and returns. It is dense and somewhat overlong, with minor redundancy around the LEARN stamp and return fields, but it remains structured and each block adds useful context.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity, the description covers selection, usage, mutation gates, dry-run behavior, side effects, and key returns. It also clarifies sibling routing and security/permission semantics, so an agent is unlikely to face major gaps when selecting or invoking it.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds meaningful cross-parameter guidance: 'subject or memory_id recommended', use_case is a label not a permission, and confirm/dry_run are runtime gates rather than authentication. This extra meaning justifies a 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific operation ('Calibrate one memory') plus the algorithm (AKM-TRIAD-1.0) and explicitly differentiates from 'ranked search' and 'explain view'. It also names sibling alternatives (memory_observe, memory_resolve, memory_get), making selection unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit positive and negative conditions: 'Use this when...' and 'Do not use it for...; use memory_observe, memory_resolve, or memory_get instead.' It further clarifies the mutation gate (confirm=true or dry_run=true), so the agent knows when calling is permitted.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memory_getExplain a memoryARead-onlyIdempotentInspect
Read one memory's stored explanation (node, history, or calibration: posterior, triad legs, effective N, Brier) — not a ranked list. Use this when you have a memory_id (or id) and need the stored explanation. Do not use it for ranked adaptive recall or appending an observation; use memory_recall or memory_observe instead. Missing both memory_id and id, or an unknown id, refuses AKM-NOT-FOUND — do not invent a node. authorizes_action stays false. There is no memory_delete; this is the read of the append-only node. Pass memory_id or id — one is enough; they are aliases, not two different records. Omit view for the default node slice. history returns events/resolutions; calibration returns posterior/triad/Brier. subject is not a lookup key here. Returns node, history, or calibration view (belief_is_not_truth).
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of memory_id. Do not send two different values. | |
| view | No | Optional slice. Omit or get = stored node; history = events/resolutions; calibration = posterior, triad legs, effective N, Brier. | |
| memory_id | No | Memory id to explain. Alternative to id. Missing both refuses AKM-NOT-FOUND. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Explain body: ok, memory_id, status, plus node or events or calibration fields. belief_is_not_truth. Refuses AKM-NOT-FOUND when the id is missing or unknown. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark readOnly/idempotent/non-destructive, and the description adds failure behavior (AKM-NOT-FOUND refusal, no invented nodes), authorization side-effect (authorizes_action stays false), and append-only nature. This is exactly the contextual behavior an agent needs beyond annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Every sentence carries a distinct fact: purpose, when-to-use, error behavior, alias handling, view semantics. Despite length, it is front-loaded and dense with no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values need no elaboration; the description covers selection criteria, error/refusal, alias usage, and sibling routing. Nothing needed to invoke correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, but description adds alias semantics ('they are aliases, not two different records'), default view behavior ('Omit view for the default node slice'), and a negative lookup constraint ('subject is not a lookup key here'). This exceeds schema detail.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Read'), resource ('one memory's stored explanation'), and explicitly contrasts with 'not a ranked list', distinguishing it from memory_recall. The title 'Explain a memory' aligns and the description names the exact views returned.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says 'Use this when you have a memory_id (or id) and need the stored explanation' and 'Do not use it for ranked adaptive recall or appending an observation; use memory_recall or memory_observe instead.' Also notes there is no memory_delete, preventing misuse.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memory_observeObserve a memoryAInspect
Append the first memory_observation to the ChainLock learn chain (AKM-TRIAD-1.0). New fact in — not an outcome resolve and not a grounded ChainLock append. Posterior ≠ truth. Use this when you have a new fact to observe before resolve/calibrate. Do not use it for grounded ChainLock append without AKM, resolving an outcome, or ranked recall; use chainlock_append, memory_resolve, or memory_recall instead. Write: additive learn-chain stamp. authorizes_action stays false. Hash-only cards refuse AKM-NO-FACT. Append-only; there is no memory_delete. fact is required (≤160). subject/memory_id/use_case optional. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns memory_id, observation stamp, and display envelope (belief is not truth).
| Name | Required | Description | Default |
|---|---|---|---|
| fact | Yes | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| subject | No | Optional subject key clipped to 80 characters. Used to find or create memory_id. | |
| use_case | No | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. | |
| memory_id | No | Optional existing memory id. Alternative to subject for resolve/calibrate/get. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description discloses append-only semantics ('there is no memory_delete'), the mutation gate (confirm=true or dry_run=true), preview behavior, specific error codes (FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, FG-LOCAL-ONLY), and that confirm is consent rather than tenant auth and does not upgrade isolation. There is no contradiction with annotations (readOnlyHint=false is consistent with a mutating tool).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a dense, single paragraph with heavy domain jargon (AKM-TRIAD-1.0, FG-*, ChainLock, hash-only cards, AKM-NO-FACT). Sentences like 'Posterior ≠ truth' and 'Write: additive learn-chain stamp' are cryptic and do not clearly help an agent decide to call the tool. It repeats information already present in the schema (e.g., fact required, confirmation gate) and lacks clear structure or front-loading, making it harder to parse than necessary.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the high complexity of this tool—multiple failure modes, mutation gates, dry-run semantics, and consent caveats—the description is thorough and covers all relevant operational details. It even explains what happens in preview mode, error codes that can be returned, and the limits of confirm as consent. Since an output schema exists, the description does not need to explain return values, and this description is complete enough for an agent to call the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema coverage is 100% and the schema itself already provides rich descriptions for every parameter, including the required fact, the confirm/dry_run behavior, and subject/memory_id/use_case. The description mostly repeats this information ('fact is required (≤160). subject/memory_id/use_case optional') and adds little new semantic meaning beyond the schema, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'Append the first memory_observation to the ChainLock learn chain'. It explicitly distinguishes this from sibling operations ('not an outcome resolve and not a grounded ChainLock append') and names the tools to use instead (chainlock_append, memory_resolve, memory_recall). An agent can tell this tool apart from its siblings without inspecting schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use guidance ('Use this when you have a new fact to observe before resolve/calibrate') and when-not-to-use guidance with specific alternatives ('Do not use it for grounded ChainLock append without AKM, resolving an outcome, or ranked recall; use chainlock_append, memory_resolve, or memory_recall instead'). This is the gold standard for usage guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memory_recallAdaptive recallARead-onlyIdempotentInspect
Ranked adaptive recall after ChainLock verify (AKM-TRIAD-1.0). Belief list — not raw grounded stamps, not a public corpus cite, not one-id explain. Use this when you want a ranked belief list after verify, not raw grounded stamps. Do not use it for grounded ChainLock recall, library search, or explaining one memory_id; use chainlock_recall, library_lookup, or memory_get instead. Does not authorize action (authorizes_action=false). Do not treat posterior rank as fact (belief_is_not_truth). Failed ChainLock verify refuses CHAIN_VERIFY_FAIL and does not invent cards. Empty grounded recall bubbles refuse=no-stamp. Ranking is capped at 16 cards. Omit depth to rank at 5 (full budget), unlike chainlock_recall which defaults to 1. q/query is lexical rank text, not a SQL filter. Empty q still verify-then-ranks stored cards. use_case weights triad_fit; it is not a permission. Optional limit clips the already-capped list. Returns ranked cards after verify (count, facts, belief_is_not_truth, authorizes_action=false).
| Name | Required | Description | Default |
|---|---|---|---|
| q | No | Optional lexical rank query (subject/fact). Alias: query. Empty still runs verify-then-rank; it does not invent facts. | |
| depth | No | Optional ChainLock recall depth after verify. Omit for 5 (full budget). 0 is tip-only ranking. | |
| limit | No | Optional result cap. Hard ceiling is 16 (MEMORY_CONTEXT_CAP) even if a larger number is sent. | |
| use_case | No | Optional use-case label that weights triad_fit in ranking. Not a permission and not a truth claim. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Adaptive recall body: ok, adaptive=true, verified, count, facts (ranked cards with score/retrieval), belief_is_not_truth, authorizes_action=false. Refuses CHAIN_VERIFY_FAIL or no-stamp. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnlyHint, openWorldHint false, idempotentHint, destructiveHint false), the description surfaces critical behavior: authorizes_action=false, belief_is_not_truth, ChainLock verify failure behavior, refusal modes, ranking caps, and default depth. This is substantial behavioral context that annotations alone do not provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense and front-loaded with the core purpose. It is longer than average and repeats a couple of points (e.g., 'not raw grounded stamps' and empty-q behavior appear more than once), but nearly every sentence adds a meaningful distinction or safety caveat, so the redundancy is minor.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given this tool's complexity, the presence of an output schema, and the rich sibling set, the description is complete: it covers failure modes, default behavior, cap limits, permission semantics, and how it differs from related tools. An agent has enough information to decide when and how to call this tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Although the input schema already covers all parameters (100% coverage), the description adds important semantics beyond the schema: q is 'lexical rank text, not a SQL filter', empty q still triggers verify-then-rank, depth defaults to 5 unlike chainlock_recall's 1, limit clips the capped list, and use_case is explicitly not a permission.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Ranked adaptive recall after ChainLock verify'. It explicitly differentiates from siblings by stating it returns a belief list 'not raw grounded stamps, not a public corpus cite, not one-id explain' and names chainlock_recall, library_lookup, and memory_get as the alternatives for those cases.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit when-to-use guidance ('Use this when you want a ranked belief list after verify') and direct when-not-to-use guidance with named alternatives ('Do not use it for grounded ChainLock recall, library search, or explaining one memory_id; use chainlock_recall, library_lookup, or memory_get instead'). It even contrasts the default depth with chainlock_recall, leaving no ambiguity about selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
memory_resolveResolve a memory outcomeAInspect
Append a memory_resolution outcome on an already-observed memory (AKM-TRIAD-1.0). UNKNOWN is distinct from MISS. Does not rewrite history. Use this when an observed memory_id or subject now has an outcome. Do not use it for first observation, calibration, or reading history; use memory_observe, memory_calibrate, or memory_get instead. Write: additive resolution stamp. Missing memory_id/subject refuses AKM-NO-MEMORY. Does not rewrite prior observations. No memory_update — this is the forward outcome path. Requires memory_id or a previously observed subject. outcome is optional [0,1]; omit for UNKNOWN. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns resolution stamp with outcome or UNKNOWN.
| Name | Required | Description | Default |
|---|---|---|---|
| fact | No | Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| outcome | No | Optional graded outcome in [0, 1]. Omit (or pass UNKNOWN) for an UNKNOWN resolution — distinct from MISS. | |
| subject | No | Optional subject key clipped to 80 characters. Used to find or create memory_id. | |
| use_case | No | Optional use-case label for calibration / adaptive recall ranking. Not a truth claim. | |
| memory_id | No | Optional existing memory id. Alternative to subject for resolve/calibrate/get. | |
| outcome_label | No | Optional label (for example HIT, MISS, GRADED, UNKNOWN). UNKNOWN is a first-class state, not a miss. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate mutation (readOnlyHint=false), but the description adds substantial behavioral detail: it is 'additive', does not rewrite prior observations, requires a runtime confirm gate, and explains dry_run semantics including which FragGate error codes it returns. It also clarifies that confirm is consent, not tenant auth, and does not upgrade isolation. This is far beyond what annotations convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but densely packed with necessary information for an 8-parameter mutation tool with multiple failure modes. It is structured with clear sentences covering purpose, usage, constraints, gating, and return value. It is slightly repetitive (e.g., 'confirm is consent' appears once in description but is also in schema), yet every sentence earns its place given the complexity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity, the description is remarkably complete: it explains the AKM-TRIAD-1.0 standard, the distinction between UNKNOWN and MISS, the additive nature, the refusal codes (AKM-NO-MEMORY, FG-HALLUC-TOOL, etc.), the confirm/dry_run gating, and the return format. The output schema likely covers the stamp structure, but the description tells the agent what to expect functionally. Nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
While schema coverage is 100%, the description adds cross-parameter meaning that the schema alone cannot: the conditional requirement 'memory_id or a previously observed subject', the optionality of outcome (omit for UNKNOWN), the mutual exclusivity of confirm and dry_run as the mutation gate, and the distinction of UNKNOWN from MISS. It explains how dry_run affects the call without writing, which is not evident from individual parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb+resource: 'Append a memory_resolution outcome on an already-observed memory', and immediately distinguishes it from siblings by saying 'Use this when an observed memory_id or subject now has an outcome' and explicitly excludes memory_observe, memory_calibrate, and memory_get. It also clarifies 'UNKNOWN is distinct from MISS' and 'Does not rewrite history', which fully differentiates it from any other tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit when-to-use and when-not-to-use guidance, naming the alternatives (memory_observe, memory_calibrate, memory_get) and the exact condition for this tool ('an observed memory_id or subject now has an outcome'). It also states the precondition 'Requires memory_id or a previously observed subject' and the mutation gate (confirm=true or dry_run=true), leaving no ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_broadcastRegister a local hash receiptAInspect
Register the SHA-256 of a local file as a hash receipt — never a publish or upload path. Use this when the operator already holds a local file and wants only its hash recorded. Do not use it for uploading bytes, publishing video, sending mail, or joining a mesh node; use local qnm-node/ anon-broadcast (local sibling, not a loopback fence of the mesh), AZMail via fraggate_call, or mesh_join instead. Write: stores a hash receipt only. Does NOT accept video bytes. Operator keeps the file. Malformed sha256 refuses MESH-BAD-INPUT; publish-shaped keys refuse MESH-NO-PUBLISH. sha256 is required (64 hex). title and product are optional labels, not file contents. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns hash receipt (sha256, optional title).
| Name | Required | Description | Default |
|---|---|---|---|
| title | No | Optional short title for the receipt. Not the file contents. | |
| sha256 | Yes | Required 64-character hex SHA-256 of the local file. Hash receipt only — not a publish path. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| product | No | Optional catalog product slug to attribute the receipt. Not required. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover only the safety profile (readOnlyHint false, destructiveHint false, openWorldHint false), and the description goes well beyond them: it discloses refusal codes (MESH-BAD-INPUT, MESH-NO-PUBLISH, MCP-CONFIRM-REQUIRED), the confirm/dry_run mutation gate, the fact that dry_run still runs allowlist/stub/hallucination checks, and that confirm is consent rather than tenant auth. That is rich behavioral context that an agent cannot get from the annotations alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded and every section carries information, but it is dense and repetitive: 'confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation' appears in the description and again in both confirm and dry_run schema descriptions. The parenthetical asides ('local sibling, not a loopback fence of the mesh') add cognitive load without adding selection value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a write tool with a rich output schema already present, the description supplies everything an agent needs: scope, exclusions, gate requirements, refusal codes, and a brief return summary. Nothing material is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3; the description nonetheless adds value by explaining the runtime semantics of confirm and dry_run (gate behavior, error codes returned) and by clarifying that title/product are labels rather than file contents. It stops short of 5 because the sha256 format detail (64 hex) merely restates the schema pattern.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource ('Register the SHA-256 of a local file as a hash receipt') and explicitly distinguishes itself from publish/upload paths and from the mesh_join sibling. The only drag is the misleading tool name 'mesh_broadcast', which implies broadcasting to a mesh; the description must work to counteract that, so the purpose is clear but not effortless to extract.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives an explicit positive condition ('when the operator already holds a local file and wants only its hash recorded') and enumerates the wrong-tool cases (uploading bytes, publishing video, sending mail, joining a mesh node) with named alternatives (local broadcast, AZMail via fraggate_call, mesh_join). This is exactly the when/when-not/alternatives structure that earns a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_disableSuite disable is refusedARead-onlyIdempotentInspect
Confirm that read-only QNM suite-presence stays ON (POST /v1/mesh/disable refuses MESH-DISABLE-REFUSED) — not a kill switch. Use this when a client still posts the historical disable route and needs the honest refuse. Do not use it for dropping one node or declaring an extra bearer; use mesh_leave or mesh_enable instead. Read-only refuse: suite-presence stays ON. No tethers drop. No implicit heal, no account resurrection, no wipe internals. Repeating still refuses. AZMail mesh_disable is a separate product-local mail ring. Returns MESH-DISABLE-REFUSED with enabled=true and a stay-on note.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, but the description adds specifics: 'No tethers drop. No implicit heal, no account resurrection, no wipe internals. Repeating still refuses.' It also clarifies the AZMail product-local mail ring, adding useful context for agent disambiguation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is structured with a clear purpose statement, usage guidance, and behavioral details. Each sentence adds value—no filler. It front-loads the core purpose and then provides necessary distinctions, making it efficient despite its length.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description covers output behavior ('Returns MESH-DISABLE-REFUSED with enabled=true and a stay-on note'), usage scenarios, and exclusions. It also addresses idempotency and the separate product ring, ensuring the agent has all needed information without external references.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, and the schema description already states 'No arguments. Send {}. Public suite disable is refused.' With 100% schema coverage, no additional parameter documentation is needed. The description focuses on behavior and usage, which is appropriate for a parameterless tool.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the tool confirms read-only QNM suite-presence stays ON and that it refuses the disable request with MESH-DISABLE-REFUSED. It also distinguishes itself from siblings by directing to mesh_leave or mesh_enable for other operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides explicit when-to-use: 'Use this when a client still posts the historical disable route and needs the honest refuse.' It also gives clear exclusions: 'Do not use it for dropping one node or declaring an extra bearer; use mesh_leave or mesh_enable instead.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_enableEnable QNM radios (declared bearer)AInspect
Declare an extra QNM suite bearer (POST /v1/mesh/enable) — additive presence, not a first-time on-switch. Use this when an operator wants to declare an additional bearer (example: suite-presence) on top of the default-on rollup. Do not use it for reading status, joining one node, turning suite-presence off, or logging into an account; use mesh_status, mesh_join, or mesh_nodes instead. Write: stores the bearer. Rate-limited. Empty {} is refused (MESH-NEED-BEARER). Login/account/recover/gate names refuse. Does not arm, wipe, heal, or resurrect accounts. Not a login mesh. Read-only suite-presence is already ON by default. bearer is required. Example: suite-presence. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns enabled state, bearers, and suite-presence note.
| Name | Required | Description | Default |
|---|---|---|---|
| bearer | Yes | Required declared bearer name. Example: suite-presence. Login / account / recover / recovery / gate / IP / publish / phoenix / heal names refuse MESH-ENABLE. This is not a login mesh. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes far beyond the annotations, disclosing that the operation writes/stores the bearer, is rate-limited, refuses empty objects and login/account/gate names, does not arm/wipe/heal/resurrect accounts, requires confirm or dry_run for mutation, and explains dry_run and confirm semantics. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but dense and front-loaded with the core purpose. Some redundancy exists, such as repeating 'confirm is consent, not tenant auth...' and bearer refusal details also present in the schema, but each sentence generally contributes behavioral or routing information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity and the presence of an output schema, the description is complete: it covers mutation gating, error conditions, dry-run behavior, authentication boundaries, what the tool does not do, and what it returns. An agent has enough context to invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Although schema coverage is 100%, the description adds substantial meaning: bearer is required with an example, empty {} is refused, mutation requires confirm=true or dry_run=true, dry_run returns specific FragGate codes, and confirm is consent rather than tenant auth. This is meaningful value beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Declare an extra QNM suite bearer (POST /v1/mesh/enable) — additive presence, not a first-time on-switch.' It clearly distinguishes mesh_enable from siblings like mesh_status, mesh_join, and mesh_nodes, and clarifies it is not a login mesh.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use the tool ('when an operator wants to declare an additional bearer') and when not to use it, naming the alternatives: 'use mesh_status, mesh_join, or mesh_nodes instead.' This gives an agent unambiguous routing guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_heartbeatRefresh QNM rollup presenceAInspect
Beat one registered node (POST /v1/mesh/heartbeat) — restores live from stale; not a first join. Use this when you already have a node_id from mesh_join and transmission radios are LIVE. Do not use it for first-time registration or dropping the node; use mesh_join or mesh_leave instead. Write: one beat on a durable session. Restores presence_class live (or locked/isolated if that was declared) from stale. Does not delete a stale row. {slug}-worker refresh still uses the strict 5-minute TTL and is not a user heartbeat. Radios off refuses MESH-OFF. A seal mismatch refuses MESH-SESSION-SEAL and does not count as live. Unknown node_id, or a row past the 14-day grace, refuses MESH-UNKNOWN-NODE — join again; no account resurrection. node_id is required. presence may replace the declared class (live|locked|isolated). heartbeat_mode may switch active|idle|asleep. Optional tip_hash and prev are 64 hex only (Split the wires + REHEAL: presence + tip hash; no body/diff/vote-to-fix). OPERATOR-OVERRIDE 2026-09-17 armed neighbor_heal. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns updated presence_class. Stale becomes the declared presence. Body on this plane refuses MESH-NO-BYTES. Same prev + two tips refuses MESH-EQUIVOCATION. Vote-to-fix still refuses MESH-NO-NEIGHBOR-HEAL.
| Name | Required | Description | Default |
|---|---|---|---|
| prev | No | Optional 64-hex prev the receiver already holds. Same prev + a different tip_hash isolates this node (MESH-EQUIVOCATION). | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| node_id | Yes | Required node id returned by mesh_join. | |
| presence | No | Optional replacement presence class. Other values refuse MESH-BAD-INPUT. | |
| tip_hash | No | Optional 64-hex tip hash on the fast tick. Fixed-size. No body. Split the wires. | |
| heartbeat_mode | No | Optional adaptive beat. active 15–30s, idle 2–5 min, asleep 15–30 min. One beat restores live from stale. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare write, non-destructive, non-idempotent, non-open-world behavior. The description adds substantial behavioral context beyond them: refusal codes, the 5-minute worker TTL distinction, confirm/dry_run gating, the fact that confirm is consent rather than tenant auth, stale-row retention, and error conditions like MESH-SESSION-SEAL and MESH-UNKNOWN-NODE.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single dense paragraph of semicolon-separated clauses, many of which repeat schema or annotation details. It is front-loaded with purpose, but the volume and lack of structure make it difficult to parse and exceed what an agent needs for tool selection.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given a complex 7-parameter mutation tool with output schema, annotations, and sibling alternatives, the description is highly complete. It covers prerequisites, side effects, refusal paths, and the confirm/dry_run runtime gate, leaving no critical invocation context missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all parameters. The description restates some semantics (node_id required, presence replacement, heartbeat_mode values, 64-hex tip_hash/prev) but adds little beyond the schema, making the baseline 3 appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'Beat one registered node (POST /v1/mesh/heartbeat) — restores live from stale; not a first join.' It distinguishes the action from mesh_join and mesh_leave, so an agent can identify it without opening the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It explicitly says when to use it: 'when you already have a node_id from mesh_join and transmission radios are LIVE.' It also states when not to use it and names alternatives: 'Do not use it for first-time registration or dropping the node; use mesh_join or mesh_leave instead.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_joinRegister QNM rollup presenceAInspect
Register one product node into the QNM rollup (POST /v1/mesh/join) — first presence, not a TTL refresh. Use this when transmission radios are LIVE and a catalog product should appear in live/locked/isolated counts. Do not use it for refreshing an existing node, reading the roster, enabling radios, or opening an account session; use mesh_heartbeat, mesh_nodes, mesh_enable, or runtime_session_open instead. Write: durable hash-sealed join session for non-worker nodes. Stay registered until explicit leave or 14 days after the last beat. heartbeat_mode active (15–30s), idle (2–5 min, default), or asleep (15–30 min). Miss 3 beats and presence_class is stale, not deleted. One beat restores the declared presence. Stale does not count as Live Nodes. Human bearers (kind=human, bearer=human, or auto-minted mesh_*) count toward public Live Nodes only while the class is live or locked. Softwares {slug}-worker rows are software_nodes, keep a strict 5-minute TTL, and never take a user heartbeat. Downloaded instance ids stay instance_nodes. Isolated humans do not count. Radios off refuses MESH-OFF. A seal mismatch refuses MESH-SESSION-SEAL. Missing product / bad node_id / bad presence / bad heartbeat_mode refuse MESH-BAD-INPUT. Downloads are not live. Read-only suite-presence is ON by default. Not an account session. AnonBroadcast is not a product. Kernel-direct fabric wrapper — same mesh kernel as FragGate mesh/join; not MASTER-33; human Join uses fraggate_call. product is required (catalog slug). node_id optional 8–80 [a-z0-9._-]. presence is live|locked|isolated (default live). heartbeat_mode is active|idle|asleep (default idle). kind/plane may be human|instance. bearer=human marks a human mesh user. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns node_id, presence_class, session_seal (sha256), registered_grace_ms, and the software 5-minute TTL note. MESH-OFF when radios are off.
| Name | Required | Description | Default |
|---|---|---|---|
| label | No | Optional short label for the roster. Display only; not a score. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| node_id | No | Optional stable node id. When set, must be 8–80 characters matching [a-z0-9._-]. Omit to receive a generated id. | |
| product | Yes | Required catalog product slug (a-z0-9-, for example godlock, azmail). AnonBroadcast is refused. Unknown slugs refuse MESH-BAD-INPUT. | |
| presence | No | Optional rollup class. live (default), locked, or isolated. No scores. Other values refuse MESH-BAD-INPUT. | |
| heartbeat_mode | No | Optional adaptive beat. active is 15–30s, idle is 2–5 min (default), asleep is 15–30 min. Miss 3 beats and the class is stale, not deleted. Ignored for {slug}-worker. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare the safety profile (readOnly=false, destructive=false, idempotent=false, openWorld=false). The description goes well beyond: durable hash-sealed join session, persistence until explicit leave or 14 days after last beat, beat-interval semantics per mode, '3 missed beats = stale, not deleted', worker 5-minute TTL, and refuse codes (MESH-OFF, MESH-SESSION-SEAL, MESH-BAD-INPUT) with their triggers. It also clarifies confirm is consent not auth. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
It is front-loaded (purpose, then routing, then behavior), but grossly oversized: a dense wall of telegraphic fragments mixing parameter restatement, refuse codes, and edge cases. Many clauses duplicate the 100%-covered schema, so the length is not proportionate to what the description needs to add.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a high-complexity mutation with an output schema present, the description covers the full lifecycle: trigger conditions, heartbeat behavior, staleness, TTL edge cases, refusal codes, and confirm/dry_run semantics. An agent has everything needed to invoke it correctly; return values are covered by the output schema.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents defaults, formats, enums, and per-param refuse codes; this sets the baseline at 3. The description largely restates that content (product required, node_id format, presence/heartbeat_mode defaults, confirm/dry_run) rather than adding much new per-parameter meaning, so it earns no lift above baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource+scope: 'Register one product node into the QNM rollup (POST /v1/mesh/join) — first presence, not a TTL refresh.' It immediately distinguishes this from the TTL-refresh sibling, so an agent can tell it apart from mesh_heartbeat without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicit when: 'Use this when transmission radios are LIVE and a catalog product should appear in live/locked/isolated counts.' Explicit when-not with named alternatives: 'Do not use it for refreshing an existing node, reading the roster, enabling radios, or opening an account session; use mesh_heartbeat, mesh_nodes, mesh_enable, or runtime_session_open instead.' Both the trigger and the routing are stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_leaveDrop QNM rollup presenceADestructiveIdempotentInspect
Drop one node from the QNM rollup (POST /v1/mesh/leave) — not a suite-wide radio off. Use this when a previously joined node should leave the counts. Do not use it for turning suite-presence off or listing nodes; use mesh_nodes or mesh_status instead. Destructive to that node's presence only. Always allowed. No implicit heal. Repeating a missing node_id is a no-op/refuse, not resurrection. node_id is required. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns leave receipt for the node_id.
| Name | Required | Description | Default |
|---|---|---|---|
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| node_id | Yes | Required node id to drop from the rollup. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true and idempotentHint=true, and the description productively extends these: it scopes destruction to 'that node's presence only', states 'No implicit heal', explains that repeating a missing node_id is a 'no-op/refuse, not resurrection', and clarifies that dry_run still returns FragGate refuse codes. This is significant behavioral context beyond the structured annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense and mostly front-loaded: purpose, usage, and exclusions appear early, followed by behavioral and gate details. It is longer than strictly necessary and somewhat repeats the 'confirm is consent, not tenant auth' point that also appears in the schema, but each sentence carries substantive guidance rather than filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity, the annotations, and the presence of an output schema, the description is complete: it covers scope, destructive effect, idempotency edge cases, confirmation/dry_run gates, error-refuse behavior, and return receipt. An agent has enough to decide when to call it and what to expect.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds meaning beyond the schema: node_id behavior on repetition, dry_run as a preview that skips writes and ledger stamps, and confirm as consent rather than tenant auth. It still relies on the schema for formal types and requiredness, but the added semantics provide real value.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description states a specific action and resource: 'Drop one node from the QNM rollup (POST /v1/mesh/leave)' and explicitly distinguishes it from 'suite-wide radio off' and from mesh_nodes/mesh_status. This gives an agent a precise mental model of what the tool does and how it differs from siblings.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit when-to-use guidance ('Use this when a previously joined node should leave the counts') and explicit when-not-to-use guidance with named alternatives ('Do not use it for turning suite-presence off or listing nodes; use mesh_nodes or mesh_status instead'). It also explains the confirm/dry_run gate required for mutation, leaving no ambiguity about invocation preconditions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_nodesList QNM rollup nodesARead-onlyIdempotentInspect
List the QNM node roster (node_id + presence_class; durable rows stay, {slug}-worker keeps a 5-minute TTL) — not suite totals. Use this when you need the current node list after mesh_status. Do not use it for suite counts without the roster, or mutating presence; use mesh_status, mesh_join, or mesh_leave instead. No scores. No leaderboard. Views/MCP/downloads do not enter QNM-S. Returns node roster with presence classes.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this a safe, idempotent read (readOnlyHint, idempotentHint, destructiveHint=false), so the safety profile is covered. The description adds genuinely new behavior beyond annotations: durable rows persist while {slug}-worker rows carry a 5-minute TTL. Return format detail is thin, but the output schema covers that.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The core purpose and routing guidance are front-loaded, which is good. However, the short fragment sentences ('No scores. No leaderboard. Views/MCP/downloads do not enter QNM-S.') read as tangential scope noise that a node-roster tool does not need, diluting an otherwise efficient statement.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values need not be re-explained, and annotations carry the safety profile. The description supplies the roster composition, TTL behavior, and sibling routing an agent needs to call this correctly, though the domain-specific 'QNM-S' clauses add confusion rather than completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are zero parameters, and the schema states 'No arguments. Send {}.' at 100% coverage, so the baseline is 4. The description correctly adds no parameter guidance because none is needed.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Starts with a specific verb and resource ('List the QNM node roster') and even enumerates the returned columns (node_id + presence_class), so the agent knows what comes back. It also distinguishes itself from suite totals and mutating siblings. The trailing jargon ('Views/MCP/downloads do not enter QNM-S') slightly muddies an otherwise crisp statement.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly states when to use it ('when you need the current node list after mesh_status') and when not to ('Do not use it for suite counts without the roster, or mutating presence'). It names the exact alternative siblings (mesh_status, mesh_join, mesh_leave) for the excluded cases, leaving nothing to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mesh_statusQNM suite rollupARead-onlyIdempotentInspect
Read QNM suite rollup totals (enabled?, bearers, nodes = human mesh users + cited human uses, live_nodes = human mesh users + site_live_viewers, software_nodes = {slug}-worker roster) — not the node roster. Packet-transfer cite is QNS-CD-1.0 (photon QNS1 1.3 on local qnsd; GET /v1/qns cites only; Worker does not proxy via emit). Use this when you need public Nodes (users + uses), Live Nodes (users + site viewers), or software_nodes (product Worker roster). Do not use it for listing individual nodes, enabling extra radios, or executing a catalog engine; use mesh_nodes, mesh_enable, or fraggate_call instead. Read-only. Never enables radios beyond default suite-presence. Read-only suite-presence is ON by default. Open-world awareness bind is 0.0.0.0 beside those radios (law LIVE; Worker socket live-when-configured; not a loopback fence; not a Cap-7 public egress IP). Not a login mesh. Views/MCP/downloads do not enter QNM-S. Full node process is local qnm-node/. Kernel-direct fabric wrapper — not MASTER-33; not a second Softwares door. Softwares exec stays fraggate_call. Returns enabled flag, bearers, nodes (human mesh users + cited uses), live_nodes (human mesh users + site_live_viewers), human_mesh_users, site_live_viewers, human_uses, active_nodes, inactive_nodes, isolated_nodes, software_nodes (product Workers), and QNS-CD-1.0 cite.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover readOnlyHint, idempotentHint, destructiveHint, and openWorldHint. The description adds meaningful context beyond those: 'Never enables radios beyond default suite-presence', 'Read-only suite-presence is ON by default', and network-binding caveats. Some of this is cryptically worded, but it does not contradict the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very long and packed with unexplained internal jargon. It is not front-loaded for quick scanning, and many clauses (e.g., 'Kernel-direct fabric wrapper — not MASTER-33; not a second Softwares door') do not clearly help an agent decide or invoke the tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a complex, zero-parameter suite-rollup tool with an output schema, the description provides ample surrounding context about scope, defaults, and exclusions. It redundantly lists return fields that the output schema already covers, but overall it gives enough to call the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters and schema coverage is 100%, so the baseline is 4. The description adds nothing about parameters because there are none to describe, which is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Read QNM suite rollup totals') and explicitly distinguishes itself from the node roster sibling via 'not the node roster' and 'use mesh_nodes instead'. The heavy domain jargon makes it harder to parse than the ideal, but the functional purpose is clear for an agent familiar with the suite.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Contains an explicit 'Use this when...' clause listing the three rollup sub-resources, and a 'Do not use it for...' clause naming the exact alternative tools (mesh_nodes, mesh_enable, fraggate_call) for each excluded case. This is as explicit as usage routing gets.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_bundleList every product (bundle helper)ARead-onlyIdempotentInspect
Read a compact bootstrap of every product skill URL and invoke prefix — not Software-tab cards and not the hashed registry. Use this when a client needs skill URLs in one shot. Do not use it for Software-tab refresh, hashed registry discovery, or exec; use Softwares, fraggate_list, or fraggate_call instead. Prefer GET /v1/software for hub Software tabs. This helper is URL bootstrap only. Returns compact product list with skill URLs.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already convey readOnly, idempotent, and non-destructive behavior. The description adds useful context that this is 'URL bootstrap only' and returns a compact product list, which clarifies scope beyond the structured data. No contradictions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is four sentences with the main purpose front-loaded, followed by usage boundaries and alternatives. Each sentence earns its place, though it could be slightly more compact without losing value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
This is a simple zero-parameter tool with an output schema present, so the description does not need to detail return values. It covers scope, exclusions, and recommended alternatives fully. An agent can confidently invoke it correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
With zero parameters and 100% schema description coverage, the schema fully documents the 'Send {}' requirement. The description reinforces this by noting it is a helper bootstrap. Baseline 4 applies since no parameter compensation is needed.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Read') and resource ('compact bootstrap of every product skill URL and invoke prefix'), and explicitly distinguishes itself from Software-tab cards and the hashed registry. It names sibling tools it is not, making differentiation trivial for an agent.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use ('when a client needs skill URLs in one shot') and when-not-to-use guidance with named alternatives (Softwares, fraggate_list, fraggate_call) and a preferred endpoint for hub Software tabs. Nothing is left to inference.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_manifestAdvanced: runtime manifestARead-onlyIdempotentInspect
[advanced/internal] Read the machine runtime manifest JSON (version, role, door=fraggate, engine slugs, registry_digest) — not the human how-to. Use this when a client needs the machine manifest rather than the human skill. Do not use it for the default agent how-to or hashed registry discovery; use runtime_skill or fraggate_list instead. Not the default agent path. Does not list hub cards or execute. Returns manifest including door=fraggate and registry_digest.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint false, and the description adds useful non-obvious context: it is an advanced/internal path, not the default agent path, and it does not list hub cards or execute. That extra scope clarification goes beyond what annotations alone convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the tool's purpose and stays reasonably compact, but there is some redundancy: 'not the human how-to', 'rather than the human skill', 'default agent how-to', and 'not the default agent path' all express a similar exclusion. Still, each main fact (purpose, alternatives, exclusions, returns) is present.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the empty input schema, the non-destructive annotations, and the presence of an output schema, the description covers everything an agent needs: what the manifest is, which fields to expect, which tools to use instead, and what the tool does not do. Nothing essential is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and 100% schema description coverage, so the schema fully documents the call signature. The description adds no parameter detail, but none is needed; the baseline of 4 for a no-parameter tool is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb ('Read'), resource ('machine runtime manifest JSON'), and enumerates key fields (version, role, door=fraggate, engine slugs, registry_digest). It also explicitly differentiates this tool from runtime_skill and fraggate_list, so an agent can distinguish it from siblings immediately.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit when-to-use guidance ('when a client needs the machine manifest rather than the human skill') and explicit when-not-to-use guidance ('Do not use it for the default agent how-to or hashed registry discovery'), naming two alternative tools. This leaves no ambiguity about selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_pullOpen one productARead-onlyIdempotentInspect
Open one hub product card by slug (name, version, skill, download, ops) — not FragGate live/stub status. Use this when you already have a slug from GET /v1/software or fraggate_list and need the card, not exec. Do not use it for inspecting FragGate live/stub status or executing an op; use fraggate_describe or fraggate_call instead. Not exec — then use fraggate_call. Unknown slug throws unknown product (it does not invent a card and does not refuse FG-HALLUC-TOOL; that code is FragGate-only). Missing skill falls back to in-repo markdown. slug is required. product is an accepted alias of slug. Extra keys besides those two are ignored and are not an op payload. Returns one product card (name, version, skill, download, ops, skill_source).
| Name | Required | Description | Default |
|---|---|---|---|
| slug | Yes | Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Alias: product. Not an exec path. | |
| product | No | Alias of slug. Do not send two different values. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | One hub product card: name, version, skill markdown, download, ops, skill_source. Unknown slug is unknown product — not a FragGate FG-HALLUC-TOOL envelope. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint false. The description goes well beyond those by disclosing error behavior for unknown slugs, the fact that it does not invent a card, the FragGate-only nature of FG-HALLUC-TOOL, the missing-skill fallback to in-repo markdown, and the ignoring of extra keys. This is rich behavioral context with no contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense and front-loaded with the core purpose, and almost every sentence adds behavioral or routing value. It loses a point for some redundancy: 'not exec' appears multiple times, and the schema already states the extra-keys behavior, so a small amount of trimming would improve clarity without losing information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only, idempotent lookup tool with an output schema, the description covers all needed context: when to use it, what it returns, how it errors, alias handling, and how it differs from related FragGate tools. Nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the schema already documents slug, product, and the alias relationship. The description adds value by reiterating that slug is required, product is an accepted alias, and extra keys are ignored rather than treated as an op payload. It slightly reinforces the schema rather than replacing it, so not a 5, but it is more than the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: 'Open one hub product card by slug' and lists the card fields. It explicitly distinguishes itself from FragGate live/stub status and exec, and names sibling alternatives, so an agent can tell it apart from fraggate_describe and fraggate_call without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit when-to-use guidance: 'Use this when you already have a slug from GET /v1/software or fraggate_list and need the card, not exec.' It also gives explicit when-not-to-use instructions and names the alternatives: 'Do not use it for inspecting FragGate live/stub status or executing an op; use fraggate_describe or fraggate_call instead.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_runAdvanced: raw runtime_runAInspect
[advanced/internal] Advanced exec façade: admit a slug+op (still DecisionGATE-admitted) and run it through a raw session. Not the default door. Use this when you were explicitly asked for the raw runtime_run path. Do not use it for the default agent exec path or an already-open session you were asked to exec on; use fraggate_call (default) or runtime_session_exec (existing session_id) instead. Side effects are operation-dependent. Not a backdoor past FragGate. Opens a session when session_id is omitted. slug and op are required for an explicit run. A question in q, question, or text with slug omitted asks the mesh router to pick one live Softwares slug and op. That pick does not exec unless confirm=true. dry_run=true returns the pick and writes nothing. session_id optional; omit to auto-open. Extra keys other than payload/session_id may be treated as payload. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns exec display envelope with session_id, result, engine_digest, ran_in, and refusal when gated.
| Name | Required | Description | Default |
|---|---|---|---|
| op | Yes | Required allowlisted op. Stubs refuse FG-STUB. | |
| slug | Yes | Required catalog slug (or name alias). Unknown slugs refuse FG-HALLUC-TOOL. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| payload | No | Optional op payload object. Engine-specific. | |
| session_id | No | Optional existing raw session id. If omitted, a session is opened automatically. Prefer leaving session plumbing invisible unless asked. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=false, openWorldHint=true, idempotentHint=false, destructiveHint=false, but the description goes well beyond them: side effects are operation-dependent, it is 'not a backdoor past FragGate,' session auto-open behavior is disclosed, dry_run semantics are detailed, refusal codes are enumerated, and confirm is explicitly distinguished from tenant auth. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with 'Advanced exec façade' and 'Not the default door,' but it is a dense wall of text with some redundancy: 'confirm is consent, not tenant auth...' appears in the description and again in schema parameter descriptions, and 'slug and op are required' is repeated. The content is valuable, but structure could be tightened with separation of concerns.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a complex, advanced internal tool with 6 parameters, nested objects, an output schema, and annotations, the description covers when to use it, when not to, session lifecycle, dry_run behavior, confirm semantics, FragGate refusal behavior, and the return envelope fields. Nothing an agent needs to select or invoke it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3. The description adds meaningful semantics beyond the schema: extra keys other than payload/session_id may be treated as payload, slug+op are required for an explicit run, and a question in q/question/text with slug omitted triggers mesh-router selection. It also clarifies confirm/dry_run interaction with the runtime gate. Minor redundancy with schema text keeps it from a 5.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb and resource ('admit a slug+op ... run it through a raw session') and immediately distinguishes itself from siblings: 'Not the default door' and explicit references to fraggate_call and runtime_session_exec. An agent can tell exactly what this tool does and how it differs from nearby alternatives.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is explicitly scoped: 'Use this when you were explicitly asked for the raw runtime_run path' and 'Do not use it for the default agent exec path or an already-open session... use fraggate_call (default) or runtime_session_exec (existing session_id) instead.' It also covers the alternative question-routing path when slug is omitted. This is model guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_closeAdvanced: seal a sessionADestructiveIdempotentInspect
[advanced/internal] Seal a raw session so further exec or policy on that session_id is rejected. End of the raw lifecycle — not a LOCKSET seal and not a FragGate call. Use this when the user asked to close the session. Do not use it for ordinary completion, writing a ChainLock LOCKSET, or default product work; use leaving the session to TTL expire (6h), chainlock_seal for a lockset, or fraggate_call for new work instead. Destructive to further exec/policy on that session_id only (session_closed 409). Does not delete receipts. A second close does not reopen — it returns session_closed (409) while the session stays sealed. Missing session returns session_not_found. Prefer leaving sessions to expire unless asked. session_id or id (aliases) required. No force flag on the public tool — TTL expiry is the automatic close path. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns sealed session status, close receipt, and verified.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of session_id. The door accepts either key; do not send two different values. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| session_id | Yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Close body: sealed session, close receipt, verified. Errors: session_id required, session_not_found, session_closed (already sealed; does not reopen). |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already signal destructive/idempotent behavior, and the description adds substantial context: destructive scope is limited to further exec/policy, receipts are not deleted, a second close returns session_closed (409), missing sessions return session_not_found, and dry_run behavior is detailed. This goes well beyond the annotation signals without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is long but well organized and front-loaded with the core action and exclusions. It earns most sentences, though it partially repeats confirm/dry_run semantics already present in the input schema, which adds slight redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a destructive, advanced internal tool, the description covers error cases, scope of effect, mutation requirements, no-force behavior, alternatives, and what the call returns. An output schema exists, so return-value details do not need to be duplicated in text.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents each parameter. The description still adds useful semantics: session_id/id alias handling, no force flag on the public tool, confirm/dry_run optionality on the required list, and the meaning of confirm as consent rather than tenant auth.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'Seal a raw session so further exec or policy on that session_id is rejected.' It also explicitly distinguishes itself from sibling tools ('not a LOCKSET seal and not a FragGate call'), making it immediately clear which operation this is.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit when-to-use guidance ('Use this when the user asked to close the session') and when-not-to-use guidance with named alternatives: 'use leaving the session to TTL expire (6h), chainlock_seal for a lockset, or fraggate_call for new work instead.' This fully routes the agent to the correct tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_execAdvanced: raw session execAInspect
[advanced/internal] Raw session exec on an already-open session_id (FragGate-admitted). Not fraggate_call and not runtime_run auto-open. Use this when you already have a session_id and were asked for raw session exec. Do not use it for the default agent exec path or opening a session; use fraggate_call or runtime_session_open instead. Side effects are operation-dependent (read, write, or refuse). Does not mint a session_id — missing id fails before admit. Sealed sessions refuse session_closed (409); TTL 6h refuses session_expired (410); receipt cap 64 refuses receipt_cap (409). Rate-limited (exec). Binding-only ops stay per-op proxy_fallback. Prefer fraggate_call. session_id or id, plus slug and op, are required for an explicit exec. A question in q, question, or text with slug omitted asks the mesh router to pick one live Softwares slug and op. That pick does not exec unless confirm=true. dry_run=true returns the pick and writes nothing. payload is optional and engine-specific; leftover keys are not auto-payload the way fraggate_call leftover keys are. Unknown slugs refuse FG-HALLUC-TOOL; stubs refuse FG-STUB. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns exec result with engine_slug, engine_op, engine_digest, ran_in, receipt, and refusal when gated.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of session_id. The door accepts either key; do not send two different values. | |
| op | Yes | Required allowlisted op. Stubs refuse FG-STUB. UI aliases still forward only after FragGate admit. | |
| slug | Yes | Required catalog slug to exec. Alias: product. Unknown slugs refuse FG-HALLUC-TOOL. This tool does not auto-open. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| outcome | No | Optional sealed status. completed marks the attempt that finished the action. retry and failed are earlier attempts. Defaults from HTTP status when omitted. | |
| payload | No | Optional op payload object. Engine-specific. Unlike fraggate_call, leftover top-level keys are not used as payload. | |
| product | No | Alias of slug. Do not send two different values. | |
| attempt_n | No | Optional 1-based attempt number. Omitted increments from the prior session receipt with the same request_id, or 1. | |
| request_id | No | Optional logical request id shared by retries of one action. Same value across attempts. Omitted mints a new id for this exec. | |
| session_id | Yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. | |
| correlation_id | No | Optional client correlation id. Sealed on the session receipt. Null when omitted. | |
| parent_receipt_id | No | Optional prior attempt receipt hash. Null on the first attempt. Omitted links to the prior session receipt with the same request_id. Not FragGate ledger prev. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Exec body: session, receipt, engine_slug, engine_op, engine_digest, ran_in, refusal when gated. Errors: session_id required, session_closed, session_expired, receipt_cap, FG-HALLUC-TOOL, FG-STUB. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only provide readOnlyHint=false, openWorldHint=true, idempotentHint=false, destructiveHint=false. The description adds substantial behavioral context: side effects are operation-dependent, missing session_id fails before admit, sealed sessions refuse session_closed (409), TTL 6h refuses session_expired (410), receipt cap 64 refuses receipt_cap (409), rate-limited (exec), binding-only ops stay per-op proxy_fallback, mutation requires confirm=true or dry_run=true, dry_run still returns refusal codes, and confirm is consent not tenant auth. This far exceeds what annotations convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is information-dense and front-loaded with the core purpose, but it is a long wall of text with many clauses packed into a few sentences. Every sentence carries information, but the density makes it harder to parse. It earns a 3 — appropriately sized for the complexity but not well-structured for quick consumption.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (13 params, nested objects, output schema, many refusal codes, routing alternatives), the description covers the critical operational context: when to use, what fails, what refuses, what confirm/dry_run mean, what the return contains, and how it differs from fraggate_call. The output schema exists, so return values need not be re-explained. Nothing essential for correct invocation is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description adds meaningful semantics beyond the schema: it explains the q/question/text alternative path where slug is omitted and the mesh router picks a slug/op, clarifies that leftover keys are not auto-payload the way fraggate_call leftover keys are, and explains the confirm/dry_run interaction. It doesn't enumerate every parameter, but the schema already covers them fully. The added semantics about the question-based routing and payload behavior justify a 4.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with '[advanced/internal] Raw session exec on an already-open session_id (FragGate-admitted)' — a specific verb, resource, and scope. It explicitly distinguishes itself from fraggate_call and runtime_run auto-open, and names sibling tools (fraggate_call, runtime_session_open) for the alternative paths. An agent can immediately tell this is the low-level exec on an existing session, not the default path.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use ('when you already have a session_id and were asked for raw session exec') and when-not-to-use ('Do not use it for the default agent exec path or opening a session; use fraggate_call or runtime_session_open instead'). It also states 'Prefer fraggate_call' as a routing preference. This is exemplary usage guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_openAdvanced: open a raw sessionAInspect
[advanced/internal] Open a raw session object (session.id). First step of open → policy → exec → receipt(s) → close. Not the default exec path. Use this when you were explicitly asked for raw session plumbing. Do not use it for the default agent exec path or attaching policy to an existing id; use fraggate_call (default) or runtime_session_policy (existing session_id) instead. Write: creates a session with a 6h TTL and receipt cap 64. Re-open on an existing id returns already=true without resetting the chain. Expired sessions refuse session_expired (410). When REQUIRE_TOKEN=1, session mutate needs RUNTIME_TOKEN; missing SESSION binding returns session_binding_missing (503). Prefer leaving sessions to TTL expire. Not chainlock_seal. Empty {} mints sess_ + 32 hex. Optional id is accepted only when it already matches that pattern; otherwise bad_session_id. source is open metadata (default worker). Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns session.id plus the first receipt in the display envelope.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Optional caller-chosen session id. Must already match sess_ + 32 lowercase hex or the open refuses bad_session_id. Omit to mint one. | |
| source | No | Optional open metadata label. Default worker. Not a permission and not a catalog slug. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Open body: session.id, receipts[0], already=true when the id already exists. Errors: bad_session_id, session_binding_missing, session_expired. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations are minimal (readOnlyHint=false, destructiveHint=false), so the description carries the full burden — and it delivers richly. It discloses 6h TTL, receipt cap 64, already=true on re-open, 410 session_expired on expired sessions, REQUIRE_TOKEN/RUNTIME_TOKEN auth, session_binding_missing 503, dry_run preview semantics with FG-HALLUC-TOOL/FG-STUB codes, and confirm as consent-not-tenant-auth. This far exceeds what annotations provide. No contradiction: 'creates a session' (write) is consistent with readOnlyHint=false.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a dense single paragraph that is information-rich but structurally flat and somewhat repetitive. The caveat 'confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation' appears three times (description, confirm param, dry_run param). Every sentence earns its place, but the redundancy and lack of structure cost it a higher score.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a complex advanced/internal tool with 4 optional params and an output schema, the description covers the full lifecycle: creation, TTL, re-open behavior, error codes, auth conditions, confirm/dry_run gates, and return value (session.id plus first receipt). Nothing an agent needs to call it correctly or predict its failure modes is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds genuine value beyond the schema: it explains the mint behavior of empty {} producing sess_ + 32 hex, the bad_session_id rejection for non-matching ids, and the interaction between confirm and dry_run (dry_run still returns refuse codes, MCP-DRY-RUN only when allowed). This elevates it above the baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'open a raw session object (session.id)' and positions it as 'First step of open → policy → exec → receipt(s) → close.' It distinguishes itself from siblings by explicitly naming fraggate_call and runtime_session_policy as the tools it is not, so an agent can tell them apart without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when/when-not guidance: 'Use this when you were explicitly asked for raw session plumbing. Do not use it for the default agent exec path or attaching policy to an existing id; use fraggate_call (default) or runtime_session_policy (existing session_id) instead.' It also states 'Not the default exec path' upfront, leaving no ambiguity about selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_policyAdvanced: attach session policyAInspect
[advanced/internal] Attach allow rules on an already-open raw session (allow_slugs / allow_ops). Policy overlay — not open and not exec. Identity remains Aziel Eliab. Use this when an already-open session needs tighter allow_slugs / allow_ops before exec. Do not use it for executing an op or opening a session; use runtime_session_exec or runtime_session_open (prefer fraggate_call, which applies defaults) instead. Write: mutates session policy only. A sealed session refuses session_closed (409). Expired sessions refuse session_expired (410). Missing both session_id and id fails before the door runs. Does not exec and does not mint a new id. session_id or id (aliases) required. allow_slugs / allow_ops replace the allow overlay when sent; omit them to leave the current lists. max_payload_bytes and kv_increment are optional overlays, not exec payload. Nested policy{} is accepted as the same overlay. Mutation requires confirm=true (runtime gate) or dry_run=true (preview only, no write). confirm and dry_run stay optional on inputSchema.required. dry_run still returns FG-HALLUC-TOOL, FG-STUB, FG-UNKNOWN-OP, or FG-LOCAL-ONLY when a confirm call would refuse. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. Returns updated session policy plus a policy receipt.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of session_id. The door accepts either key; do not send two different values. | |
| confirm | No | Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation. | |
| dry_run | No | Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation. | |
| allow_ops | No | Optional replacement allowlist of ops this session may exec. Omit to keep the current list. | |
| session_id | Yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. | |
| allow_slugs | No | Optional replacement allowlist of catalog slugs this session may exec. Omit to keep the current list. | |
| kv_increment | No | Optional. When true, allow KV increment side effects on later exec. Not an increment itself. | |
| max_payload_bytes | No | Optional max payload size in bytes for later exec (integer 1..1048576). Overlay only; not the exec body. Out of range refuses bad_policy. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Policy body: updated session allow lists and a policy receipt. Refuses session_id required, session_not_found, session_closed, session_expired. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Discloses much more than the sparse annotations: 'mutates session policy only,' 'Does not exec and does not mint a new id,' sealed sessions return 409, expired sessions return 410, and dry_run returns specific refuse codes. This gives the agent a precise behavioral model.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense and runs as one long paragraph, but it is front-loaded with action and usage before behavioral details. Some redundancy exists (e.g., confirm semantics also appear in schema descriptions), yet the length is largely justified by the tool's complexity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Covers when to use, when not to use, error cases, dry_run behavior, confirm requirements, return value ('Returns updated session policy plus a policy receipt'), and parameter overlay semantics. With an output schema present, no critical information is missing for an agent to invoke this correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3. The description adds meaning beyond the schema by explaining overlay semantics: 'allow_slugs / allow_ops replace the allow overlay when sent; omit them to leave the current lists,' and 'max_payload_bytes and kv_increment are optional overlays, not exec payload.' Also notes nested policy{} is accepted.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific action and resource: 'Attach allow rules on an already-open raw session (allow_slugs / allow_ops).' It also distinguishes itself from siblings by explicitly saying 'Policy overlay — not open and not exec,' making its role clear.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides explicit when-to-use guidance: 'Use this when an already-open session needs tighter allow_slugs / allow_ops before exec.' It names alternatives and exclusions: 'Do not use it for executing an op or opening a session; use runtime_session_exec or runtime_session_open (prefer fraggate_call...) instead.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_receiptAdvanced: last session receiptARead-onlyIdempotentInspect
[advanced/internal] Read the last receipt only for a raw session — not the full chain. Use this when the user asked for the latest receipt on an open or sealed session. Do not use it for the full receipt chain or product output the user did not ask to audit; use runtime_session_receipts (full chain) or the product display from fraggate_call instead. Does not mutate the session. Unknown id returns session_not_found. An empty receipt list returns receipt=null rather than inventing one. Prefer product output (display) unless the user asked for the chain. session_id or id (aliases) required. No view/limit — this is always the last receipt plus a chain verified flag. Returns the last receipt object (or null) and verified.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of session_id. The door accepts either key; do not send two different values. | |
| session_id | Yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Last-receipt body: receipt (or null), verified chain flag, public session. Errors: session_id required, session_not_found. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and destructiveHint, so the safety profile is covered. The description adds valuable behavioral context beyond annotations: it does not mutate the session, unknown ids return session_not_found, and an empty receipt list returns receipt=null rather than inventing one. It also clarifies there is no view/limit and that a chain verified flag accompanies the result.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is longer than average, but every sentence earns its place: purpose, usage, exclusions, alternatives, side-effect safety, error semantics, parameter aliasing, and return shape are all covered without fluff. The most important scoping information is front-loaded in the first sentence.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity, the presence of an output schema, and the sibling set, the description is complete. It covers selection criteria, exclusions, error behavior, empty-result behavior, parameter requirements, and output shape, leaving no practical gap for an agent deciding whether and how to call it.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents both session_id and id thoroughly. The description adds useful semantic guidance by confirming the aliases are interchangeable, warning against sending two different values, and explicitly stating that no view/limit parameter exists. This goes slightly beyond the schema but does not need to carry the full burden.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with a specific verb and resource: 'Read the last receipt only for a raw session — not the full chain.' It explicitly distinguishes this tool from the sibling runtime_session_receipts by contrasting 'last receipt only' with 'full chain,' so an agent can tell them apart immediately.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives explicit when-to-use guidance ('when the user asked for the latest receipt on an open or sealed session') and explicit when-not-to-use guidance with named alternatives: runtime_session_receipts for the full chain and fraggate_call for product display. It also adds a clear preference rule: 'Prefer product output (display) unless the user asked for the chain.'
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_session_receiptsAdvanced: session receipt chainARead-onlyIdempotentInspect
[advanced/internal] Read the full receipt chain for a raw session — not the last receipt only. Use this when the user asked for the whole receipt chain. Do not use it for only the last receipt or ordinary product output; use runtime_session_receipt or the product display from fraggate_call instead. Does not mutate the session. Unknown id returns session_not_found. List is the stored chain (cap 64), oldest to newest, plus verified. Prefer product output unless the user asked for the chain. session_id or id (aliases) required. No pagination — the cap is the runtime receipt cap, not a cursor. Returns the receipt list (capped at 64) and verified.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Alias of session_id. The door accepts either key; do not send two different values. | |
| session_id | Yes | Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found. |
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Receipt-chain body: receipts[] (cap 64), verified, public session. Errors: session_id required, session_not_found. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, but the description goes well beyond them by explaining the unknown-id error, the cap of 64, oldest-to-newest ordering, the inclusion of 'verified', and the no-pagination semantics. This materially enriches what an agent knows before calling.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is dense but every sentence earns its place: the core purpose is front-loaded, the exclusion is immediate, and each following sentence adds a distinct behavioral or routing fact. There is no filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the annotations, the schema, and the output schema, the description covers everything an agent needs: usage routing, mutation safety, error case, result shape, ordering, cap, and pagination behavior. No critical gap remains.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents session_id, its pattern, the alias id, and the rule against sending two different values. The description repeats the alias requirement but adds no new parameter-level meaning beyond the schema, so the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource: 'Read the full receipt chain for a raw session' and explicitly contrasts it with 'not the last receipt only.' It also names the sibling tools that handle the alternatives, so an agent can distinguish runtime_session_receipts from runtime_session_receipt and fraggate_call without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives explicit when-to-use guidance ('Use this when the user asked for the whole receipt chain'), explicit when-not-to-use guidance ('Do not use it for only the last receipt or ordinary product output'), and names the alternatives with routing. The closing instruction to 'Prefer product output unless the user asked for the chain' leaves no ambiguity.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
runtime_skillHow to use this softwareARead-onlyIdempotentInspect
Read the agent how-to (one door — discover, route, refuse; pipeline fraggate_list → fraggate_describe → fraggate_call). This is playbook markdown, not a catalog and not a machine manifest. Use this when starting a session or choosing the door before any catalog call. Do not use it for listing hashed registry names, hub Software-tab cards, or executing an engine; use fraggate_list, Softwares, or fraggate_call instead. Dual surface: agent chat has no technical UI chrome; Worker / Flutter / local install stay complete human software. Does not list slugs or run ops. Returns skill markdown plus display.title / display.summary.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish readOnlyHint, idempotentHint, and non-destructive behavior. The description adds meaningful behavioral context beyond those annotations: it returns skill markdown plus display.title/display.summary, does not list slugs or run operations, and functions as a dual-surface playbook rather than a catalog. This is richer than a bare read-only declaration, though it does not address topics like rate limits or auth.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core action and includes several dense but purposeful sentences that clarify scope, alternatives, and return contents. Every sentence contributes either to the tool's identity or to routing the agent correctly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter, read-only tool with a rich output schema and clear annotations, the description fully covers invocation, scope boundaries, return shape, and sibling routing. Nothing essential is missing for an agent to select and call this tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and the schema description already states 'No arguments. Send {}' with 100% coverage, so the baseline of 4 applies. The description adds no parameter ambiguity and reinforces that invocation requires no arguments.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific action ('Read the agent how-to') and names the artifact it returns (skill markdown plus display fields). It also explicitly distinguishes itself from siblings by saying it is 'not a catalog and not a machine manifest' and by referencing the alternative tools fraggate_list and fraggate_call.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives precise when-to-use guidance: 'starting a session or choosing the door before any catalog call.' It also gives explicit when-not-to-use guidance with named alternatives: listing hashed registry names, hub Software-tab cards, or executing an engine should use fraggate_list, Softwares, or fraggate_call.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
SoftwaresFirst call — pick a Softwares slugARead-onlyIdempotentInspect
Read the Softwares catalog and pick a slug (first call). Not the hashed live/stub registry. Use this when an agent starts, or a hub refreshes the Software tab, and a slug is needed before fraggate_call. Do not use it for executing that slug, hashed live/stub discovery, or library papers; use fraggate_call after the slug is picked, fraggate_list for hashes, or library_lookup for papers instead. Empty {} only. Never enables mesh radios and never execs. tools/list name is Softwares. runtime_software is a tools/call alias and is not a second listed tool. Same JSON as GET /v1/software (also /v1/fraggate/software). Cards carry name, slug, ops, worker_home — not live/stub/digest hashes. EmbryoLock is live-with-local-destructive-boundary (worker_home embryolock-download-tracker). Plain A–Z → Gate A–Z → Lock A–Z (Clock ≠ Lock), including AZChat LIVE+bound. After this catalog, pick a slug and call fraggate_call. library_lookup is for library papers and cites. Returns sorted software cards (name, slug, ops, worker_home) matching GET /v1/software.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| code | No | FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*. |
| door | No | Door name. The public door is fraggate. |
| ran_in | No | Execution locale (for example aziel-runtime) when present. |
| result | No | Software-tab catalog JSON (products/cards with name, slug, ops, worker_home, sort lanes Plain→Gate→Lock). Not a hashed registry roster. |
| status | No | HTTP-like status when present on wrappers (200 ok; 400+ error / refuse). |
| display | No | Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names. |
| receipt | No | Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one. |
| refusal | No | Explicit refuse object, code, or message when the door or engine refused. |
| engine_op | No | Resolved engine op when present (often inside result). |
| ledger_tip | No | Ask/refuse ledger tip when the door stamped one. |
| provenance | No | Provenance / input packet when the pipeline attached one. |
| session_id | No | Raw session id when session plumbing was used. Hidden unless the user asked for the chain. |
| engine_slug | No | Resolved engine slug when present (often inside result). |
| limitations | No | Capability limitations or Remain-OFF notes when present. |
| engine_digest | No | 64-hex engine_digest when a true in-process engine ran (often inside result). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive/openWorld=false, yet the description adds real value: 'Never enables mesh radios and never execs', the tools/call alias mapping (runtime_software), and the exact card fields returned. It does not cover pagination or rate/limit behavior, so it stops short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The first sentence front-loads the purpose well, but the body is padded: the slug-then-fraggate_call instruction is stated twice, and cryptic fragments ('Plain A–Z → Gate A–Z → Lock A–Z (Clock ≠ Lock)', 'EmbryoLock is live-with-local-destructive-boundary') add length without clear operational payoff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need not be explained, yet the description still summarizes card contents and the REST equivalence. Usage, aliases, and safety are all covered; only the opaque acronym-chain content slightly muddies an otherwise complete picture.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Zero parameters with 100% schema coverage, so the baseline is 4; the description reinforces 'Empty {} only.', which matches the schema and removes any ambiguity about sending arguments.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Read the Softwares catalog and pick a slug (first call)') and explicitly separates itself from the 'hashed live/stub registry'. It names the sibling tools it is not (fraggate_call, fraggate_list, library_lookup), so an agent can route without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use ('when an agent starts, or a hub refreshes the Software tab, and a slug is needed before fraggate_call'), explicit when-not ('Do not use it for executing that slug, hashed live/stub discovery, or library papers') and names each alternative with its condition.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
v2.0.11- Changed
mesh_heartbeat1 field changed- added
Input schema / properties / heartbeat_modeAdded value: +{ + "description": "Optional adaptive beat. active 15–30s, idle 2–5 min, asleep 15–30 min. One beat restores live from stale.", + "enum": [ + "active", + "idle", + "asleep" + ], + "type": "string" +}
- Changed
mesh_join1 field changed- added
Input schema / properties / heartbeat_modeAdded value: +{ + "description": "Optional adaptive beat. active is 15–30s, idle is 2–5 min (default), asleep is 15–30 min. Miss 3 beats and the class is stale, not deleted. Ignored for {slug}-worker.", + "enum": [ + "active", + "idle", + "asleep" + ], + "type": "string" +}
36 tool updates
v2.0.9- Changed
chainlock_append5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
chainlock_recall5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
chainlock_seal5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
chainlock_tip5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
chainlock_verify5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
decisiongate_check5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
fraggate_call5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
fraggate_describe5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
fraggate_list5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
fraggate_verify5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
library_lookup5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
memory_calibrate5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
memory_get5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
memory_observe5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
memory_recall5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
memory_resolve5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_broadcast5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_disable5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_enable5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_heartbeat5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_join5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_leave5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_nodes5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
mesh_status5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_bundle5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_manifest5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_pull5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_run5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_close5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_exec5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_open5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_policy5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_receipt5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_session_receipts5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
runtime_skill5 fields changed- changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
- Changed
Softwares6 fields changed- changed
Input schema / descriptionPrevious value: -"No arguments. Send {}. Hub/client helper — not exec and not fraggate_list."New value: +"No arguments. Send {}. First call — pick a slug, then fraggate_call. Not exec and not fraggate_list." - changed
Output schema / descriptionPrevious value: -"Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear."New value: +"Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names." - changed
Output schema / properties / display / descriptionPrevious value: -"Human-facing envelope. Show title and summary, then take the next input."New value: +"Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names." - added
Output schema / properties / display / properties / actionAdded value: +{ + "description": "Human-visible run frame. Always \"Run aziel runtime\". Product verb titles stay on title. Not a tool name.", + "type": "string" +} - added
Output schema / properties / display / properties / imageAdded value: +{ + "additionalProperties": true, + "description": "Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.", + "properties": { + "data": { + "description": "Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.", + "type": "string" + }, + "mimeType": { + "description": "Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).", + "type": "string" + }, + "reviewed": { + "description": "True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.", + "type": "boolean" + }, + "source": { + "description": "Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).", + "type": "string" + }, + "url": { + "description": "Cited http(s) image URL when the production named one. Not invented.", + "type": "string" + } + }, + "type": "object" +} - changed
Output schema / properties / display / properties / title / descriptionPrevious value: -"Short result title for the AI client."New value: +"Product verb title for the AI client. Not a raw tool name."
19 tool updates
v2.0.8- Changed
chainlock_append2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
chainlock_seal2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
decisiongate_check2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
fraggate_call5 fields changed- changed
Input schema / descriptionPrevious value: -"Required: op. Also pass slug or name. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id become the op payload when payload is omitted. Mutation requires confirm=true or dry_run=true."New value: +"Required: op, unless job_id is set. Also pass slug or name. Shorthand foldlock/fold-preview is accepted. Mutation requires confirm=true or dry_run=true. background=true returns Running until a receipt hash exists." - added
Input schema / properties / backgroundAdded value: +{ + "description": "Optional. When true, FragGate admits the call and returns Running with a job_id before the op finishes. Done is returned only after a receipt hash exists. dry_run does not start a job. A missing job is Quiet, not Done.", + "type": "boolean" +} - changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation." - added
Input schema / properties / job_idAdded value: +{ + "description": "Optional job id from a background call (job_ + 16 hex). When set, the call reads that job and does not start another. confirm=true is still required. It does not re-run the op.", + "pattern": "^job_[a-f0-9]{16}$", + "type": "string" +}
- Changed
memory_calibrate2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
memory_observe2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
memory_resolve2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
mesh_broadcast2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
mesh_enable2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
mesh_heartbeat2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
mesh_join2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
mesh_leave2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
runtime_run2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
runtime_session_close2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
runtime_session_exec2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
runtime_session_open2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Changed
runtime_session_policy2 fields changed- changed
Input schema / properties / confirm / descriptionPrevious value: -"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write)."New value: +"Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation." - changed
Input schema / properties / dry_run / descriptionPrevious value: -"Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate."New value: +"Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation."
- Removed
runtime_software - Added
Softwares
2 tool updates
v2.0.3- Changed
fraggate_call4 fields changed- added
Input schema / properties / attempt_nAdded value: +{ + "description": "Optional 1-based attempt number for this call. Omitted means attempt 1 of a new request_id.", + "minimum": 1, + "type": "integer" +} - added
Input schema / properties / correlation_idAdded value: +{ + "description": "Optional client correlation id. Sealed inside a ForgeReceipts hash when this call mints one.", + "nullable": true, + "type": "string" +} - added
Input schema / properties / parent_receipt_idAdded value: +{ + "description": "Optional prior attempt receipt hash. Null on the first attempt. This is not FragGate ledger prev, which stays call order only.", + "nullable": true, + "type": "string" +} - added
Input schema / properties / request_idAdded value: +{ + "description": "Optional logical request id. The same value groups retries of one action on the ResultEnvelope and, for ForgeReceipts, inside the receipt hash.", + "type": "string" +}
- Changed
runtime_session_exec5 fields changed- added
Input schema / properties / attempt_nAdded value: +{ + "description": "Optional 1-based attempt number. Omitted increments from the prior session receipt with the same request_id, or 1.", + "minimum": 1, + "type": "integer" +} - added
Input schema / properties / correlation_idAdded value: +{ + "description": "Optional client correlation id. Sealed on the session receipt. Null when omitted.", + "nullable": true, + "type": "string" +} - added
Input schema / properties / outcomeAdded value: +{ + "description": "Optional sealed status. completed marks the attempt that finished the action. retry and failed are earlier attempts. Defaults from HTTP status when omitted.", + "enum": [ + "retry", + "failed", + "completed" + ], + "type": "string" +} - added
Input schema / properties / parent_receipt_idAdded value: +{ + "description": "Optional prior attempt receipt hash. Null on the first attempt. Omitted links to the prior session receipt with the same request_id. Not FragGate ledger prev.", + "nullable": true, + "type": "string" +} - added
Input schema / properties / request_idAdded value: +{ + "description": "Optional logical request id shared by retries of one action. Same value across attempts. Omitted mints a new id for this exec.", + "type": "string" +}
17 tool updates
v2.0.2- Changed
chainlock_append3 fields changed- changed
Input schema / descriptionPrevious value: -"fact is required. Omit c/chain to stamp session. Extra keys such as s/f/kind are aliases; they do not change the append-only rule."New value: +"fact is required. Omit c/chain to stamp session. Extra keys such as s/f/kind are aliases; they do not change the append-only rule. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
chainlock_seal3 fields changed- changed
Input schema / descriptionPrevious value: -"No required arguments. Empty {} seals current live tips. Optional ts is TemporalLock metadata only."New value: +"No required arguments. Empty {} seals current live tips. Optional ts is TemporalLock metadata only. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
decisiongate_check3 fields changed- changed
Input schema / descriptionPrevious value: -"All fields optional. Empty proposals still run the five gates and stamp the ledger."New value: +"All schema fields optional. Empty proposals still run the five gates and stamp the ledger. Live stamp still needs confirm=true at tools/call, or dry_run=true for a preview." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
fraggate_call3 fields changed- changed
Input schema / descriptionPrevious value: -"Required: op. Also pass slug or name. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id become the op payload when payload is omitted."New value: +"Required: op. Also pass slug or name. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id become the op payload when payload is omitted. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
memory_calibrate3 fields changed- changed
Input schema / descriptionPrevious value: -"subject or memory_id recommended. Extra keys are accepted."New value: +"subject or memory_id recommended. Extra keys are accepted. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
memory_observe3 fields changed- changed
Input schema / descriptionPrevious value: -"fact is required. subject/memory_id/use_case optional."New value: +"fact is required. subject/memory_id/use_case optional. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
memory_resolve3 fields changed- changed
Input schema / descriptionPrevious value: -"Requires memory_id or a previously observed subject. outcome may be omitted for UNKNOWN. Extra keys are accepted."New value: +"Requires memory_id or a previously observed subject. outcome may be omitted for UNKNOWN. Extra keys are accepted. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
mesh_broadcast3 fields changed- changed
Input schema / descriptionPrevious value: -"sha256 is required (64 hex). This is a receipt, not a blob upload."New value: +"sha256 is required (64 hex). This is a receipt, not a blob upload. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
mesh_enable3 fields changed- changed
Input schema / descriptionPrevious value: -"bearer is required. Empty object is MESH-ENABLE refuse."New value: +"bearer is required. Empty object is MESH-ENABLE refuse. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
mesh_heartbeat3 fields changed- changed
Input schema / descriptionPrevious value: -"node_id is required. Missing node_id refuses MESH-BAD-INPUT."New value: +"node_id is required. Missing node_id refuses MESH-BAD-INPUT. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
mesh_join3 fields changed- changed
Input schema / descriptionPrevious value: -"product is required. presence must be live|locked|isolated when set. node_id must be 8–80 [a-z0-9._-]."New value: +"product is required. presence must be live|locked|isolated when set. node_id must be 8–80 [a-z0-9._-]. Radios off refuses MESH-OFF. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
mesh_leave3 fields changed- changed
Input schema / descriptionPrevious value: -"node_id is required. Missing node_id refuses MESH-BAD-INPUT."New value: +"node_id is required. Missing node_id refuses MESH-BAD-INPUT. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
runtime_run3 fields changed- changed
Input schema / descriptionPrevious value: -"slug and op are required. Extra keys other than payload/session_id may be treated as payload."New value: +"slug and op are required. Extra keys other than payload/session_id may be treated as payload. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
runtime_session_close3 fields changed- changed
Input schema / descriptionPrevious value: -"session_id or id required. Extra keys are ignored. This is not chainlock_seal."New value: +"session_id or id required. Extra keys are ignored. This is not chainlock_seal. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
runtime_session_exec3 fields changed- changed
Input schema / descriptionPrevious value: -"session_id (or id), slug, and op are required. Extra keys besides payload are not treated as the op payload."New value: +"session_id (or id), slug, and op are required. Extra keys besides payload are not treated as the op payload. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
runtime_session_open3 fields changed- changed
Input schema / descriptionPrevious value: -"No required arguments. Empty {} mints a sess_ + 32 hex id. Extra keys may be stored as open metadata."New value: +"No required arguments. Empty {} mints a sess_ + 32 hex id. Extra keys may be stored as open metadata. Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
- Changed
runtime_session_policy3 fields changed- changed
Input schema / descriptionPrevious value: -"session_id or id required. Other fields are optional policy overlays (also accepted nested under policy)."New value: +"session_id or id required. Other fields are optional policy overlays (also accepted nested under policy). Mutation requires confirm=true or dry_run=true." - added
Input schema / properties / confirmAdded value: +{ + "description": "Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true (preview, no write).", + "type": "boolean" +} - added
Input schema / properties / dry_runAdded value: +{ + "description": "Optional preview flag. When true, return a would-mutate preview and do not write. Alternative to confirm=true. Does not mutate.", + "type": "boolean" +}
19 tool updates
v2.0.1- Changed
chainlock_append7 fields changed- changed
Input schema / descriptionPrevious value: -"fact is required (≤160). Hash-only cards without a fact refuse."New value: +"fact is required. Omit c/chain to stamp session. Extra keys such as s/f/kind are aliases; they do not change the append-only rule." - changed
Input schema / properties / c / descriptionPrevious value: -"Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain."New value: +"Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to stamp the session chain." - added
Input schema / properties / chainAdded value: +{ + "description": "Alias of c. Omit both to stamp the session chain.", + "enum": [ + "genesis", + "identity", + "ssh", + "session", + "acts", + "evidence", + "recall", + "mesh", + "library", + "learn" + ], + "type": "string" +} - changed
Input schema / properties / fact / descriptionPrevious value: -"Required fact text clipped to 160 characters. Hash-only / empty fact refuses."New value: +"Required fact text clipped to 160 characters. Empty or hash-only after clip refuses no-fact. Alias: f." - changed
Input schema / properties / k / descriptionPrevious value: -"Optional kind label for the stamp."New value: +"Optional kind label. Omit to store kind stamp. Alias: kind." - changed
Input schema / properties / subject / descriptionPrevious value: -"Optional subject clipped to 80 characters."New value: +"Optional subject clipped to 80 characters. Alias: s." - changed
Output schema / properties / result / descriptionPrevious value: -"FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB."New value: +"Append body: ok, stamp (id, c, k, fact, fh, stamp_sha256, prev), card, seq, vault path. Refuses: no-fact, unknown-chain, card-cap."
- Changed
chainlock_recall5 fields changed- changed
Input schema / descriptionPrevious value: -"All fields optional. depth is 0 (tip) through 5 (genesis/budget)."New value: +"All fields optional. Default depth is 1. Default chains are session, acts, recall, learn." - changed
Input schema / properties / c / descriptionPrevious value: -"Optional chain name to recall from. Omit to use the default recall path."New value: +"Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to scan session, acts, recall, and learn — not the full roster." - added
Input schema / properties / chainAdded value: +{ + "description": "Alias of c. Omit both to scan session, acts, recall, and learn — not the full roster.", + "enum": [ + "genesis", + "identity", + "ssh", + "session", + "acts", + "evidence", + "recall", + "mesh", + "library", + "learn" + ], + "type": "string" +} - changed
Input schema / properties / depth / descriptionPrevious value: -"Optional recall depth. 0 = tip only; 5 = genesis/budget maximum. Values outside 0–5 are clipped."New value: +"Optional recall depth. Omit for 1. 0 = tip only; 5 = genesis/budget maximum. Values outside 0–5 are clipped. Alias: d." - changed
Input schema / properties / q / descriptionPrevious value: -"Optional query string to filter recalled cards. Does not invent matches."New value: +"Optional case-insensitive substring over subject/fact. Alias: query. Empty does not invent matches."
- Changed
chainlock_seal3 fields changed- changed
Input schema / descriptionPrevious value: -"No required arguments. Optional ts may be passed through as TemporalLock timestamp metadata."New value: +"No required arguments. Empty {} seals current live tips. Optional ts is TemporalLock metadata only." - changed
Input schema / properties / ts / descriptionPrevious value: -"Optional ISO-8601 timestamp for the TemporalLock block. Omit to use now. Does not backdate authority."New value: +"Optional ISO-8601 timestamp copied onto the TemporalLock block. Omit to use now. Never backdates authority, prior stamps, or godlock.uk." - changed
Output schema / properties / result / descriptionPrevious value: -"FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB."New value: +"Seal body: ok, lockset (members, temporal, godlock, lockset_sha256), or refuse empty-vault when no live tips exist. Does not write godlock.uk."
- Changed
chainlock_tip4 fields changed- changed
Input schema / descriptionPrevious value: -"c selects the chain. Omit for the default tip path."New value: +"Omit c/chain to read the session chain tip. Extra properties are rejected." - changed
Input schema / properties / c / descriptionPrevious value: -"Optional chain name from the ChainLock roster."New value: +"Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to read the session chain tip." - added
Input schema / properties / chainAdded value: +{ + "description": "Alias of c. Omit both to read the session chain tip.", + "enum": [ + "genesis", + "identity", + "ssh", + "session", + "acts", + "evidence", + "recall", + "mesh", + "library", + "learn" + ], + "type": "string" +} - changed
Output schema / properties / result / descriptionPrevious value: -"FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB."New value: +"Tip body: ok, chain, tip card or null, empty flag, seq when a stamp exists. Empty chain is ok+empty, not an invented card."
- Changed
chainlock_verify4 fields changed- changed
Input schema / descriptionPrevious value: -"Optional chain selector. Extra keys are ignored by verify."New value: +"Optional chain selector. Omit to verify the live vault / LOCKSET." - changed
Input schema / properties / c / descriptionPrevious value: -"Optional chain name to focus verify. Omit to verify the live vault / LOCKSET."New value: +"Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to verify every roster chain plus the stored LOCKSET." - added
Input schema / properties / chainAdded value: +{ + "description": "Alias of c. Omit both to verify every roster chain plus the stored LOCKSET.", + "enum": [ + "genesis", + "identity", + "ssh", + "session", + "acts", + "evidence", + "recall", + "mesh", + "library", + "learn" + ], + "type": "string" +} - added
Input schema / properties / require_sealAdded value: +{ + "description": "Optional. When true, fail-closed if receipts/LOCKSET.json is missing. When omitted, a stored lockset is still checked if present.", + "type": "boolean" +}
- Changed
fraggate_verify1 field changed- changed
Input schema / descriptionPrevious value: -"Provide name, slug, and/or digest. Digest-only checks the whole registry hash."New value: +"Provide name, slug, and/or digest. Empty {} refuses FG-HALLUC-TOOL. Digest-only checks the whole registry hash."
- Changed
library_lookup1 field changed- changed
Input schema / properties / q / descriptionPrevious value: -"Optional query string for op=search. Empty q returns an empty or default hit set, not an invented cite."New value: +"Optional public-corpus query for op=search. Empty q returns an empty or default hit set, not an invented cite. Not a memory or ChainLock query."
- Changed
memory_get5 fields changed- changed
Input schema / descriptionPrevious value: -"Pass memory_id or id. view selects the explain slice."New value: +"Pass memory_id or id (aliases). Omit view for the node slice. Extra properties are rejected." - changed
Input schema / properties / id / descriptionPrevious value: -"Alias of memory_id."New value: +"Alias of memory_id. Do not send two different values." - changed
Input schema / properties / memory_id / descriptionPrevious value: -"Memory id to explain. Alternative to id."New value: +"Memory id to explain. Alternative to id. Missing both refuses AKM-NOT-FOUND." - changed
Input schema / properties / view / descriptionPrevious value: -"Optional view: get (default node), history, or calibration."New value: +"Optional slice. Omit or get = stored node; history = events/resolutions; calibration = posterior, triad legs, effective N, Brier." - changed
Output schema / properties / result / descriptionPrevious value: -"FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB."New value: +"Explain body: ok, memory_id, status, plus node or events or calibration fields. belief_is_not_truth. Refuses AKM-NOT-FOUND when the id is missing or unknown."
- Changed
memory_recall6 fields changed- changed
Input schema / descriptionPrevious value: -"All fields optional. depth follows ChainLock 0–5."New value: +"All fields optional. Default depth is 5. Empty q still runs verify-then-rank and does not invent facts." - changed
Input schema / properties / depth / descriptionPrevious value: -"Optional recall depth 0–5 after ChainLock verify."New value: +"Optional ChainLock recall depth after verify. Omit for 5 (full budget). 0 is tip-only ranking." - added
Input schema / properties / limitAdded value: +{ + "description": "Optional result cap. Hard ceiling is 16 (MEMORY_CONTEXT_CAP) even if a larger number is sent.", + "maximum": 16, + "minimum": 1, + "type": "number" +} - changed
Input schema / properties / q / descriptionPrevious value: -"Optional query to rank against. Empty query still runs verify-then-rank; it does not invent facts."New value: +"Optional lexical rank query (subject/fact). Alias: query. Empty still runs verify-then-rank; it does not invent facts." - changed
Input schema / properties / use_case / descriptionPrevious value: -"Optional use-case label that weights ranking. Not a permission."New value: +"Optional use-case label that weights triad_fit in ranking. Not a permission and not a truth claim." - changed
Output schema / properties / result / descriptionPrevious value: -"FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB."New value: +"Adaptive recall body: ok, adaptive=true, verified, count, facts (ranked cards with score/retrieval), belief_is_not_truth, authorizes_action=false. Refuses CHAIN_VERIFY_FAIL or no-stamp."
- Changed
mesh_disable1 field changed- changed
Input schema / descriptionPrevious value: -"No arguments. Send {}. Always allowed."New value: +"No arguments. Send {}. Public suite disable is refused."
- Changed
mesh_heartbeat2 fields changed- added
Input schema / properties / prevAdded value: +{ + "description": "Optional 64-hex prev the receiver already holds. Same prev + a different tip_hash isolates this node (MESH-EQUIVOCATION).", + "type": "string" +} - added
Input schema / properties / tip_hashAdded value: +{ + "description": "Optional 64-hex tip hash on the fast tick. Fixed-size. No body. Split the wires.", + "type": "string" +}
- Changed
runtime_pull4 fields changed- changed
Input schema / descriptionPrevious value: -"slug is required. Extra keys are ignored by the pull helper."New value: +"slug or product required. Extra keys are ignored by the pull helper — not an exec payload." - added
Input schema / properties / productAdded value: +{ + "description": "Alias of slug. Do not send two different values.", + "type": "string" +} - changed
Input schema / properties / slug / descriptionPrevious value: -"Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Not an exec path."New value: +"Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Alias: product. Not an exec path." - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"One hub product card: name, version, skill markdown, download, ops, skill_source. Unknown slug is unknown product — not a FragGate FG-HALLUC-TOOL envelope."
- Changed
runtime_session_close5 fields changed- changed
Input schema / descriptionPrevious value: -"session_id is required."New value: +"session_id or id required. Extra keys are ignored. This is not chainlock_seal." - added
Input schema / properties / idAdded value: +{ + "description": "Alias of session_id. The door accepts either key; do not send two different values.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - changed
Input schema / properties / session_id / descriptionPrevious value: -"Required session id to seal. Further exec on this id is rejected."New value: +"Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found." - added
Input schema / properties / session_id / patternAdded value: +"^sess_[a-f0-9]{32}$" - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Close body: sealed session, close receipt, verified. Errors: session_id required, session_not_found, session_closed (already sealed; does not reopen)."
- Changed
runtime_session_exec9 fields changed- changed
Input schema / descriptionPrevious value: -"session_id, slug, and op are required."New value: +"session_id (or id), slug, and op are required. Extra keys besides payload are not treated as the op payload." - added
Input schema / properties / idAdded value: +{ + "description": "Alias of session_id. The door accepts either key; do not send two different values.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - changed
Input schema / properties / op / descriptionPrevious value: -"Required allowlisted op. Stubs refuse FG-STUB."New value: +"Required allowlisted op. Stubs refuse FG-STUB. UI aliases still forward only after FragGate admit." - changed
Input schema / properties / payload / descriptionPrevious value: -"Optional op payload object. Engine-specific."New value: +"Optional op payload object. Engine-specific. Unlike fraggate_call, leftover top-level keys are not used as payload." - added
Input schema / properties / productAdded value: +{ + "description": "Alias of slug. Do not send two different values.", + "type": "string" +} - changed
Input schema / properties / session_id / descriptionPrevious value: -"Required open session id. Alias: id."New value: +"Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found." - added
Input schema / properties / session_id / patternAdded value: +"^sess_[a-f0-9]{32}$" - changed
Input schema / properties / slug / descriptionPrevious value: -"Required catalog slug to exec. Unknown slugs refuse FG-HALLUC-TOOL."New value: +"Required catalog slug to exec. Alias: product. Unknown slugs refuse FG-HALLUC-TOOL. This tool does not auto-open." - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Exec body: session, receipt, engine_slug, engine_op, engine_digest, ran_in, refusal when gated. Errors: session_id required, session_closed, session_expired, receipt_cap, FG-HALLUC-TOOL, FG-STUB."
- Changed
runtime_session_open4 fields changed- changed
Input schema / descriptionPrevious value: -"No required arguments. Extra keys may be stored as open metadata. Prefer fraggate_call."New value: +"No required arguments. Empty {} mints a sess_ + 32 hex id. Extra keys may be stored as open metadata." - added
Input schema / properties / idAdded value: +{ + "description": "Optional caller-chosen session id. Must already match sess_ + 32 lowercase hex or the open refuses bad_session_id. Omit to mint one.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - added
Input schema / properties / sourceAdded value: +{ + "description": "Optional open metadata label. Default worker. Not a permission and not a catalog slug.", + "type": "string" +} - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Open body: session.id, receipts[0], already=true when the id already exists. Errors: bad_session_id, session_binding_missing, session_expired."
- Changed
runtime_session_policy11 fields changed- changed
Input schema / descriptionPrevious value: -"session_id is required. Other fields are optional policy overlays."New value: +"session_id or id required. Other fields are optional policy overlays (also accepted nested under policy)." - changed
Input schema / properties / allow_ops / descriptionPrevious value: -"Optional allowlist of ops this session may exec."New value: +"Optional replacement allowlist of ops this session may exec. Omit to keep the current list." - changed
Input schema / properties / allow_slugs / descriptionPrevious value: -"Optional allowlist of catalog slugs this session may exec."New value: +"Optional replacement allowlist of catalog slugs this session may exec. Omit to keep the current list." - added
Input schema / properties / idAdded value: +{ + "description": "Alias of session_id. The door accepts either key; do not send two different values.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - changed
Input schema / properties / kv_increment / descriptionPrevious value: -"Optional. When true, allow KV increment side effects on this session."New value: +"Optional. When true, allow KV increment side effects on later exec. Not an increment itself." - changed
Input schema / properties / max_payload_bytes / descriptionPrevious value: -"Optional max payload size in bytes for later exec."New value: +"Optional max payload size in bytes for later exec (integer 1..1048576). Overlay only; not the exec body. Out of range refuses bad_policy." - added
Input schema / properties / max_payload_bytes / maximumAdded value: +1048576 - added
Input schema / properties / max_payload_bytes / minimumAdded value: +1 - changed
Input schema / properties / session_id / descriptionPrevious value: -"Required raw session id from runtime_session_open. Alias: id."New value: +"Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found." - added
Input schema / properties / session_id / patternAdded value: +"^sess_[a-f0-9]{32}$" - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Policy body: updated session allow lists and a policy receipt. Refuses session_id required, session_not_found, session_closed, session_expired."
- Changed
runtime_session_receipt5 fields changed- changed
Input schema / descriptionPrevious value: -"session_id is required."New value: +"session_id or id required. Extra keys are ignored." - added
Input schema / properties / idAdded value: +{ + "description": "Alias of session_id. The door accepts either key; do not send two different values.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - changed
Input schema / properties / session_id / descriptionPrevious value: -"Required session id whose last receipt to read. Alias: id."New value: +"Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found." - added
Input schema / properties / session_id / patternAdded value: +"^sess_[a-f0-9]{32}$" - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Last-receipt body: receipt (or null), verified chain flag, public session. Errors: session_id required, session_not_found."
- Changed
runtime_session_receipts5 fields changed- changed
Input schema / descriptionPrevious value: -"session_id is required."New value: +"session_id or id required. Extra keys are ignored. No cursor/limit." - added
Input schema / properties / idAdded value: +{ + "description": "Alias of session_id. The door accepts either key; do not send two different values.", + "pattern": "^sess_[a-f0-9]{32}$", + "type": "string" +} - changed
Input schema / properties / session_id / descriptionPrevious value: -"Required session id whose receipt list to read. Alias: id."New value: +"Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found." - added
Input schema / properties / session_id / patternAdded value: +"^sess_[a-f0-9]{32}$" - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Receipt-chain body: receipts[] (cap 64), verified, public session. Errors: session_id required, session_not_found."
- Changed
runtime_software2 fields changed- changed
Input schema / descriptionPrevious value: -"No arguments. Send {}. Hub/client helper — not exec."New value: +"No arguments. Send {}. Hub/client helper — not exec and not fraggate_list." - changed
Output schema / properties / result / descriptionPrevious value: -"Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip."New value: +"Software-tab catalog JSON (products/cards with name, slug, ops, worker_home, sort lanes Plain→Gate→Lock). Not a hashed registry roster."
36 tool updates
v1.6.2- Added
chainlock_append - Added
chainlock_recall - Added
chainlock_seal - Added
chainlock_tip - Added
chainlock_verify - Changed
decisiongate_check8 fields changed- added
Input schema / descriptionAdded value: +"All fields optional. Empty proposals still run the five gates and stamp the ledger." - added
Input schema / properties / accountable / descriptionAdded value: +"Optional accountable party string." - added
Input schema / properties / evidence / descriptionAdded value: +"Optional evidence strings. Missing evidence can fail a gate." - added
Input schema / properties / impact_neg / descriptionAdded value: +"Optional negative-impact list." - added
Input schema / properties / impact_pos / descriptionAdded value: +"Optional positive-impact list." - added
Input schema / properties / statement / descriptionAdded value: +"Optional proposal statement to evaluate." - added
Input schema / properties / values / descriptionAdded value: +"Optional values list." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
fraggate_call10 fields changed- added
Input schema / descriptionAdded value: +"Required: op. Also pass slug or name. Extra top-level keys other than name/slug/product/tool/op/verb/claim/proposal/ground/payload/session_id/id become the op payload when payload is omitted." - added
Input schema / properties / claim / additionalPropertiesAdded value: +true - changed
Input schema / properties / claim / descriptionPrevious value: -"Optional DecisionGATE proposal (statement, evidence, impacts, values, accountable)"New value: +"Optional DecisionGATE proposal attached to this call. Also runs automatically inside the door even when omitted (defaults). Freedom without clarity is chaos." - added
Input schema / properties / claim / propertiesAdded value: +{ + "accountable": { + "description": "Optional accountable party. Identity on this runtime is Aziel Eliab only.", + "type": "string" + }, + "evidence": { + "description": "Optional evidence strings supporting the statement.", + "items": { + "type": "string" + }, + "type": "array" + }, + "impact_neg": { + "description": "Optional negative impacts.", + "items": { + "type": "string" + }, + "type": "array" + }, + "impact_pos": { + "description": "Optional positive impacts.", + "items": { + "type": "string" + }, + "type": "array" + }, + "statement": { + "description": "Optional proposal statement (what is being asked).", + "type": "string" + }, + "values": { + "description": "Optional values the proposal claims to honor.", + "items": { + "type": "string" + }, + "type": "array" + } +} - changed
Input schema / properties / name / descriptionPrevious value: -"Registry name or slug"New value: +"Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL." - changed
Input schema / properties / op / descriptionPrevious value: -"Public allowlisted op"New value: +"Required public allowlisted op from fraggate_describe (for example fold-preview, ethical_search, blank_key_status). UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, doctor, pair) forward to catalog ops. Unknown ops refuse FG-UNKNOWN-OP; stubs refuse FG-STUB." - added
Input schema / properties / payload / additionalPropertiesAdded value: +true - added
Input schema / properties / payload / descriptionAdded value: +"Optional op payload object. Shape is engine-specific (see fraggate_describe). Malformed fields are refused by the engine, not by this door schema. If omitted, leftover top-level keys are used as the payload." - added
Input schema / properties / slug / descriptionAdded value: +"Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
fraggate_describe5 fields changed- changed
Input schema / additionalPropertiesPrevious value: -trueNew value: +false - added
Input schema / descriptionAdded value: +"Exactly one of name or slug is enough. Extra properties are rejected by the schema; the door still only reads name/slug." - added
Input schema / properties / name / descriptionAdded value: +"Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL." - added
Input schema / properties / slug / descriptionAdded value: +"Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
fraggate_list4 fields changed- changed
Input schema / additionalPropertiesPrevious value: -trueNew value: +false - added
Input schema / descriptionAdded value: +"No arguments. Send {}. Discovery first — not describe or execute." - added
Input schema / propertiesAdded value: +{} - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
fraggate_verify7 fields changed- changed
Input schema / additionalPropertiesPrevious value: -trueNew value: +false - added
Input schema / descriptionAdded value: +"Provide name, slug, and/or digest. Digest-only checks the whole registry hash." - added
Input schema / properties / digest / descriptionAdded value: +"Optional 64-char lowercase hex engine_digest or registry digest to verify. When digest is set without name/slug, the tool compares the live registry digest." - added
Input schema / properties / digest / patternAdded value: +"^[a-fA-F0-9]{64}$" - added
Input schema / properties / name / descriptionAdded value: +"Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL." - added
Input schema / properties / slug / descriptionAdded value: +"Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
library_lookup5 fields changed- added
Input schema / descriptionAdded value: +"q is the search text. op selects the library verb. Extra keys are forwarded as corpus payload." - changed
Input schema / properties / op / descriptionPrevious value: -"search (default), example, or skill"New value: +"Optional library verb. search (default) looks up public corpus text; example returns a sample; skill returns the library skill; health is liveness. Other values refuse FG-UNKNOWN-OP." - added
Input schema / properties / op / enumAdded value: +[ + "search", + "example", + "skill", + "health" +] - added
Input schema / properties / q / descriptionAdded value: +"Optional query string for op=search. Empty q returns an empty or default hit set, not an invented cite." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Added
memory_calibrate - Added
memory_get - Added
memory_observe - Added
memory_recall - Added
memory_resolve - Added
mesh_broadcast - Added
mesh_disable - Added
mesh_enable - Added
mesh_heartbeat - Added
mesh_join - Added
mesh_leave - Added
mesh_nodes - Added
mesh_status - Changed
runtime_bundle4 fields changed- changed
Input schema / additionalPropertiesPrevious value: -trueNew value: +false - added
Input schema / descriptionAdded value: +"No arguments. Send {}." - added
Input schema / propertiesAdded value: +{} - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_manifest3 fields changed- added
Input schema / descriptionAdded value: +"No required arguments. Extra keys are ignored." - added
Input schema / propertiesAdded value: +{} - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_pull3 fields changed- added
Input schema / descriptionAdded value: +"slug is required. Extra keys are ignored by the pull helper." - added
Input schema / properties / slug / descriptionAdded value: +"Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Not an exec path." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_run7 fields changed- added
Input schema / descriptionAdded value: +"slug and op are required. Extra keys other than payload/session_id may be treated as payload." - added
Input schema / properties / op / descriptionAdded value: +"Required allowlisted op. Stubs refuse FG-STUB." - added
Input schema / properties / payload / additionalPropertiesAdded value: +true - added
Input schema / properties / payload / descriptionAdded value: +"Optional op payload object. Engine-specific." - added
Input schema / properties / session_id / descriptionAdded value: +"Optional existing raw session id. If omitted, a session is opened automatically. Prefer leaving session plumbing invisible unless asked." - added
Input schema / properties / slug / descriptionAdded value: +"Required catalog slug (or name alias). Unknown slugs refuse FG-HALLUC-TOOL." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_close3 fields changed- added
Input schema / descriptionAdded value: +"session_id is required." - added
Input schema / properties / session_id / descriptionAdded value: +"Required session id to seal. Further exec on this id is rejected." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_exec7 fields changed- added
Input schema / descriptionAdded value: +"session_id, slug, and op are required." - added
Input schema / properties / op / descriptionAdded value: +"Required allowlisted op. Stubs refuse FG-STUB." - added
Input schema / properties / payload / additionalPropertiesAdded value: +true - added
Input schema / properties / payload / descriptionAdded value: +"Optional op payload object. Engine-specific." - added
Input schema / properties / session_id / descriptionAdded value: +"Required open session id. Alias: id." - added
Input schema / properties / slug / descriptionAdded value: +"Required catalog slug to exec. Unknown slugs refuse FG-HALLUC-TOOL." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_open3 fields changed- added
Input schema / descriptionAdded value: +"No required arguments. Extra keys may be stored as open metadata. Prefer fraggate_call." - added
Input schema / propertiesAdded value: +{} - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_policy7 fields changed- added
Input schema / descriptionAdded value: +"session_id is required. Other fields are optional policy overlays." - added
Input schema / properties / allow_ops / descriptionAdded value: +"Optional allowlist of ops this session may exec." - added
Input schema / properties / allow_slugs / descriptionAdded value: +"Optional allowlist of catalog slugs this session may exec." - added
Input schema / properties / kv_increment / descriptionAdded value: +"Optional. When true, allow KV increment side effects on this session." - added
Input schema / properties / max_payload_bytes / descriptionAdded value: +"Optional max payload size in bytes for later exec." - added
Input schema / properties / session_id / descriptionAdded value: +"Required raw session id from runtime_session_open. Alias: id." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_receipt3 fields changed- added
Input schema / descriptionAdded value: +"session_id is required." - added
Input schema / properties / session_id / descriptionAdded value: +"Required session id whose last receipt to read. Alias: id." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_session_receipts3 fields changed- added
Input schema / descriptionAdded value: +"session_id is required." - added
Input schema / properties / session_id / descriptionAdded value: +"Required session id whose receipt list to read. Alias: id." - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Changed
runtime_skill4 fields changed- changed
Input schema / additionalPropertiesPrevious value: -trueNew value: +false - added
Input schema / descriptionAdded value: +"No arguments. Send {}. Returns the agent skill text." - added
Input schema / propertiesAdded value: +{} - changed
Output schema / (root)Previous value: -nullNew value: +{ + "additionalProperties": true, + "description": "Display envelope shown to the user (display.title / display.summary) plus the machine result. Extra engine fields may appear.", + "properties": { + "code": { + "description": "FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.", + "type": "string" + }, + "display": { + "additionalProperties": true, + "description": "Human-facing envelope. Show title and summary, then take the next input.", + "properties": { + "fields": { + "description": "Optional labeled scalars copied from the result for display.", + "items": { + "additionalProperties": true, + "properties": { + "label": { + "description": "Field label.", + "type": "string" + }, + "value": { + "description": "Field value as text.", + "type": "string" + } + }, + "type": "object" + }, + "type": "array" + }, + "next": { + "description": "What the agent should do after showing this output.", + "type": "string" + }, + "summary": { + "description": "One-line outcome or refuse reason.", + "type": "string" + }, + "title": { + "description": "Short result title for the AI client.", + "type": "string" + } + }, + "type": "object" + }, + "door": { + "description": "Door name. The public door is fraggate.", + "type": "string" + }, + "engine_digest": { + "description": "64-hex engine_digest when a true in-process engine ran (often inside result).", + "type": "string" + }, + "engine_op": { + "description": "Resolved engine op when present (often inside result).", + "type": "string" + }, + "engine_slug": { + "description": "Resolved engine slug when present (often inside result).", + "type": "string" + }, + "ledger_tip": { + "description": "Ask/refuse ledger tip when the door stamped one." + }, + "limitations": { + "description": "Capability limitations or Remain-OFF notes when present." + }, + "provenance": { + "description": "Provenance / input packet when the pipeline attached one." + }, + "ran_in": { + "description": "Execution locale (for example aziel-runtime) when present.", + "type": "string" + }, + "receipt": { + "description": "Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one." + }, + "refusal": { + "description": "Explicit refuse object, code, or message when the door or engine refused." + }, + "result": { + "description": "Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip." + }, + "session_id": { + "description": "Raw session id when session plumbing was used. Hidden unless the user asked for the chain.", + "type": "string" + }, + "status": { + "description": "HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).", + "type": "integer" + } + }, + "type": "object" +}
- Added
runtime_software
TDQS
Scored across 36 tools
The tools span distinct subsystems (mesh, ChainLock, AKM memory, FragGate, raw sessions), and descriptions explicitly cross-reference alternatives. However, multiple exec doors (fraggate_call, runtime_run, runtime_session_exec) and parallel recall/append paths (chainlock_* vs memory_*) create real misselection risk despite the verbose warnings.
Most tools follow a snake_case prefix_action pattern (mesh_join, chainlock_append, runtime_session_open). Deviations exist: 'Softwares' is capitalized and noun-only, and runtime_* mixes verbs and nouns (runtime_run, runtime_bundle, runtime_manifest). Mixed but still largely readable.
36 tools is well above the 3–15 sweet spot and exceeds the 25+ threshold for 'too many'. While the server covers many subsystems, the surface is sprawling and includes redundant advanced/internal doors.
Core lifecycles are covered: session open→policy→exec→receipt→close, mesh join/heartbeat/leave/status, ChainLock append/tip/recall/verify/seal, memory observe/resolve/calibrate/recall/get. Minor gaps exist (e.g., mesh_disable is a refuse rather than a real off switch, no delete paths by design), but agents can work around them.
Maintenance
Related MCP Connectors
Discover and call 10,000+ production APIs from one MCP server. Pay-per-call billing for AI agents.
The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call.
Connect MCP clients to 2,000+ AI models without managing provider API keys.
- 0bridgeOAuthdev.0bridge
Every service you connect, one MCP endpoint for all your AI tools. Sign in once.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to access a unified catalog of tools from various APIs (OpenAPI, GraphQL, MCP, Google Discovery) through the MCP protocol.20 npmMIT
- AlicenseNot gradedqualityDmaintenanceAggregates multiple OpenAPI specifications into a single searchable MCP server, enabling AI agents to query API endpoints across all services using natural language.MIT
- AlicenseNot gradedqualityCmaintenanceFederates MCP, A2A, and REST/gRPC APIs with centralized governance, discovery, and observability, optimizing agent and tool calling with plugin support.Apache 2.0
- AlicenseAqualityAmaintenanceEnables AI harnesses to connect to a single MCP endpoint that routes to multiple downstream MCP servers, discovering and executing capabilities on demand while keeping tool schemas out of context.470 npmApache 2.0