{
  "tool_id": "art-150-mcp-tool-scope-revocation-auditor",
  "kernel_id": "art-150-mcp-tool-scope-revocation-auditor",
  "display_name": "MCP Tool Scope & Revocation Auditor",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Audit scoped and revocable MCP tool access per the new MCP specification: each granted tool must carry an explicit scope array, a revocation endpoint must be configured (https-scheme), and token rotation posture (max age vs elapsed time, next-key presence) must be healthy. Emits per-tool grant verdict and gap list. Feeds the on-behalf-of mandate validator (art-151). Zero network, zero PII.",
  "control_description": "Audit scoped and revocable MCP tool access per the new MCP specification: each granted tool must carry an explicit scope array, a revocation endpoint must be configured (https-scheme), and token rotation posture (max age vs elapsed time, next-key presence) must be healthy. Emits per-tool grant verdict and gap list. Feeds the on-behalf-of mandate validator (art-151). Zero network, zero PII.",
  "declared_inputs": [],
  "declared_outputs": [
    "art-151-agent-obo-mandate-validator"
  ],
  "kernel_digest": "sha256:fd6f63b8a386c172c843a6c2a5382c56af85518a8498a55b1a9b8caee294df78",
  "trust_label": "deferred -- deterministic source published, zkVM proof not yet generated",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 27,
  "source_url": "https://ainumbers.co/chaingraph/art-150-mcp-tool-scope-revocation-auditor.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
