CAIN-42 claim
C42-MCPGATE-SCHEMA-RESIDENCY
An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass.
Last reviewed 2026-10-01
SIMULATED
The claim
An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass.
Level SIMULATED is how far the evidence goes: TESTED means a test suite exercised it, LIVE means it was observed on the hosted system. Nothing is claimed beyond its level.
| category | MCP ENFORCEMENT |
|---|---|
| status | TESTED |
| evidence level meaning | automated test evidence |
| limits | the flag is OFF in production, so no production traffic has used it; A+++ gate 6 passes on the proxy code path, the overall A+++ verdict stays BLOCKED; single-host in-process measurements |
| verification method | in the repository: python3 -m pytest -q tests/test_mcp_residency_router.py; bundle integrity: MANIFEST.json |
| revalidate by | 2026-12-30T03:20:13Z |
| claim version | 1 |
Evidence files
Verify this signed claim in your browser
Checks the whole registry's Ed25519 signature against the published evidence-root key, then re-hashes this claim's artifact files. Same algorithm as the standalone verify_claims.py.
From CAIN-42 signed public claims registry.
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem