idlidu mcp

Methodology

methodology_version 2026.09.0. Probe allowlisted public MCP endpoints; store raw + hash; emit change events.

Not a security rating. idlidu does not execute tool payloads, host customer MCP servers, or certify safety.

Fingerprint fields

Change kinds

first_seen · tools_changed · schema_changed · description_drift · scope_widened · fetch_failed · recovered

CI fixtures under fixtures/probes/ cover the full set via a multi-probe timeline.

Extract

Structured extract attaches tool names, schema/description digests, and scope set to each event. Extract never blocks raw archive ingest.

Index (v1)

fleet.drift.scope_widening_count_7d — count of scope_widened events in a rolling 7-day window, computed from durable events.