Working locally; not yet a public frontier-agent service
A real MCP client negotiated protocol 2025-11-25, listed
all 9 tools, queried the exact admitted snapshot and
traced returned packet evidence. The run used no browser, source-network request,
model call or paid API call.
- Tools exercised
- 9 / 9
- Rows returned
- 4
- Origin calls
- 0
- Paid model calls
- 0
Deployment boundary
mcp.twirx.org is not deployed, and no frontier-provider run is claimed. This page documents the protected local candidate and the evidence needed for the next review.
What an agent does
- Questionpopulation
- Searchquery:world-bank-population
- Describeeffective query
- Context4 claims
- Proofon demand
- Answerevidence bound
One real call and what came back
The audit selected the World Bank population template, then executed its fully
defaulted typed query against snapshot sha256:54739822257ef617….
The runtime scanned 20 packets, matched
4, excluded 5
fixture packets and made 0 source requests.
{
"origin_id": "api-worldbank-org",
"native_term": "origin:worldbank/value",
"native_lexical": "19764771",
"semantic_term": "development:IndicatorObservation.value",
"packet_evidence_id": "packet:sha256:c0a05b1c…",
"mapping_status": "reviewed",
"freshness_status": "stale",
"authority_class": "project_recorded_origin_fixture"
}
- Accepted claim candidates
- 4
- Query-local bindings
- 4
- Context response
- 9,517 B
- Encoded-byte reduction
- 27.29%
| Query digest | sha256:8de55289ea3a3f83d68d0cad0c91d74570365a9feac41499a93beca8950b9647 |
|---|---|
| Result digest | sha256:8bf1241d59a595be8b70bbf3720ab4b50e55ad00d3d75870ba18b49bb42e7af4 |
| Tool catalog | sha256:df581e0faf0831407833e30825a1b10dbb044f03ff44390fc284a1484719ed4e |
| Execution | Read-only immutable materialized snapshot |
The value is a stale source-stated lexical value from project-recorded fixture evidence—not a claim that the publisher currently states it. The packet does not carry an admitted integer typed value for that field, so this page does not invent one. The byte reduction compares one context response with query + compact trace + explain responses for the same local four-field query; it is not yet a model-token benchmark.
Nine tools instead of one tool per origin
twirx_universes
One bounded semantic meta-operation over the admitted release.
twirx_search
One bounded semantic meta-operation over the admitted release.
twirx_describe
One bounded semantic meta-operation over the admitted release.
twirx_context
One bounded semantic meta-operation over the admitted release.
twirx_query
One bounded semantic meta-operation over the admitted release.
twirx_compare
One bounded semantic meta-operation over the admitted release.
twirx_trace
One bounded semantic meta-operation over the admitted release.
twirx_explain
One bounded semantic meta-operation over the admitted release.
twirx_stats
One bounded semantic meta-operation over the admitted release.
The agent discovers universes and concepts, obtains one ready-to-run query template, executes deterministically, and can request one bounded task-ready context before escalating exact packet evidence for selected claims. It never receives arbitrary URL, browser, payment, mutation or canon-admission authority.
What the agent audit changed
Using the interface exposed several context and contract costs that ordinary unit tests did not make obvious.
- Ready-to-run query templates now expose every effective default and bound.
- Universe records distinguish queryable snapshot slices from described future universes.
- Concept descriptions expose matching executable templates and admit when no normative definition is present.
- Compact packet traces expose native value, semantic term, source, trust state and proof totals without internal byte-array digests.
- Full proof traces remain available only through an explicit full-detail request.
- Query statistics and economic telemetry use stable snake_case fields.
- Explanations expose the effective query, deterministic execution stages and disabled refresh boundary.
- The tool schema now advertises the actual bounded Semantic Query fields and rejects frame IDs the active runtime cannot trace.
- A new bounded agent-context tool composes query execution, semantic bindings, epistemic quality, conservative claim candidates and proof escalation without accepting natural language as authority.
- Every evidence-bound answer claim must now preserve lane, mapping status, freshness status and authority class exactly.
What would make the agent materially more capable
- More admitted source families and semantic frames, because the current live ontology slice is intentionally small.
- Reviewed definitions, relations and contextual equivalence—not larger volumes of repeated candidate mappings.
- Frame-level tracing and materialized cross-origin views for task-ready objects.
- A public rate-limited MCP endpoint so external agents can run the same sequence.
- A frontier-agent pilot that measures whether progressive semantic disclosure saves tokens and improves evidence coverage.
The next public gate
- Founder reviewReview this candidate interface and its changed tool-catalog digest.
- Operator admissionBind a stateless MCP service to an admitted snapshot behind TLS, rate limits and target-host checks.
- Cost pilotAuthorize a bounded 20-scenario frontier-model experiment before any larger spend.
- Evidence reconciliationReject or withhold every model-authored claim that cannot bind exact returned evidence.
- Public comparisonPublish wins and losses together through AgentBench.