methodology_version 2026.09.0. Probe allowlisted public MCP endpoints; store raw + hash; emit change events.
content_hash — full tool list + scopes + probe statustools_hash · schema_hash · description_hash · scopes_hashstatus — ok or fetch_failed first_seen · tools_changed ·
schema_changed · description_drift ·
scope_widened · fetch_failed ·
recovered
CI fixtures under fixtures/probes/ cover the full set via a
multi-probe timeline.
Structured extract attaches tool names, schema/description digests, and scope set to each event. Extract never blocks raw archive ingest.
fleet.drift.scope_widening_count_7d — count of
scope_widened events in a rolling 7-day window, computed from
durable events.