CAIN-42 invariant · E27
I-POLDIST-mcp_server-downgrade: downgrade refused role mcp_server
Held · CAIN-42 Evolution 27 -- Agentic Internet Control Plane
Last reviewed 2026-10-01
held niche Policy, law & governance · family policy_distribution
What this rule means
CAIN-42 must always satisfy: downgrade refused role mcp_server. It is one of 757 invariants checked for CAIN-42 Evolution 27 -- Agentic Internet Control Plane. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.
Recorded detail
['POLICY_DOWNGRADE_REFUSED']Verify it in your browser
Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).
Check it yourself
Browse the raw bundle · How to reproduce it · SHA-256 manifest
Scope: {"limitation": "An in-process control-plane library. It coordinates E25/E26; enforcement remains in the E8 boundary. No hosted service, no external peer.", "status": "SCOPE"}
Related rules
- I-POLDIST-gateway-publish: publish role gateway
- I-POLDIST-gateway-accept: accept role gateway
- I-POLDIST-gateway-downgrade: downgrade refused role gateway
- I-POLDIST-agent-publish: publish role agent
- I-POLDIST-agent-accept: accept role agent
- I-POLDIST-agent-downgrade: downgrade refused role agent
- I-POLDIST-runtime-publish: publish role runtime
- I-POLDIST-runtime-accept: accept role runtime
← I-POLDIST-mcp_server-accept · all 757 · I-POLDIST-a2a_endpoint-publish →
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem