CAIN-42 CAIN Studio

CAIN-42 claim

C42-MCPGATE-SCHEMA-RESIDENCY

An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass.

Last reviewed 2026-10-01

SIMULATED

The claim

An authorization-aware MCPGate router library keeps tool schemas in PINNED, HOT, WARM, COLD or EVICTED context residency by a deterministic score (frequency, recency, task similarity, dependencies, tenant affinity) and never lets residency decide a call: every call's schema is the canonical, digest-checked one, the CAIN authorizer receives no residency information and its DENY is final even for a flooded HOT tool, an evicted tool is still callable only through full authorization, canonical schemas are never deleted, every decision is hash-chained evidence, and limits produce backpressure. Measured on one host: active context 6-31x smaller than exposing every schema (50-1,000 tools). It is wired into the MCPGate proxy (cain/mcp_proxy.py) behind CAIN_MCP_RESIDENCY: with residency on and off every tools/call decision is identical, and 20 of 20 bypass tests pass.

Level SIMULATED is how far the evidence goes: TESTED means a test suite exercised it, LIVE means it was observed on the hosted system. Nothing is claimed beyond its level.

categoryMCP ENFORCEMENT
statusTESTED
evidence level meaningautomated test evidence
limitsthe flag is OFF in production, so no production traffic has used it; A+++ gate 6 passes on the proxy code path, the overall A+++ verdict stays BLOCKED; single-host in-process measurements
verification methodin the repository: python3 -m pytest -q tests/test_mcp_residency_router.py; bundle integrity: MANIFEST.json
revalidate by2026-12-30T03:20:13Z
claim version1

Evidence files

Verify this signed claim in your browser

Checks the whole registry's Ed25519 signature against the published evidence-root key, then re-hashes this claim's artifact files. Same algorithm as the standalone verify_claims.py.

From CAIN-42 signed public claims registry.

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem