Society & Economicspreprint2026-09-07

Declared vs. Observed: Measuring the Binding Gap in MCP Tool Declarations

Open access0 citations

Abstract

Pre-execution authority controls for tool-using agents take a declaration as their input: a claim, written by the tool's publisher, about what the action does. The claim is treated as a property of the tool. It is a statement about a contract at a moment, and the contract moves. We measure how far apart those two things have drifted. Across 35 crawls of the public Model Context Protocol registry between June and August 2026, covering 44,172 tools on 2,043 servers, 83.8% of tools declare at least one canonical effect annotation, and 59.3% hold a declaration still bound to an unmutated contract. The difference, 24.5 percentage points, is the distance between what a declaration-gated system believes it has verified and what remains attested. It is stable from 21.6 to 24.7 points across every corroboration and observation threshold tested, and it is not concentrated: the ten largest contributors hold 14.1% of stale tools. Over the longest uninterrupted 21-day window, 18.3% of the declaring and judgeable tools in that window saw a confirmed contract mutation, which is the rate a staleness clock has to outrun. Declarations also move on their own, and the movement that matters is not the one a monitor watches for. The corpus holds 783 confirmed declaration changes. All four annotation defaults are restrictive, so a first declaration on the permissive pole moves a tool, from a gate's point of view, from assumed-restricted to declared-permissive with no change event to fire on: 86.0% of first declarations land permissive, a rate that holds between 83.4% and 94.0% under the omission of any single publisher. The operational consequence is a difference in kind rather than degree. Under the schema conditional, a re-approval trigger would have to fire on 445 tools; a watcher keyed to value flips reaches 62. A flip-watcher cannot fire on a first declaration at all. We report each population under one definition at a time, with and without the schema conditional that makes two annotations meaningful only when a third is false, because applying it means taking a publisher's claim at face value and a reader may decline to. The corpus, the per-tool records and the verifier are published under CC BY 4.0 and cited by version DOI, so every figure here recomputes from the released files rather than resting on this description of them.

// Source

View paper (DOI)Open access versionOpenAlexarXiv (Cornell University)Published 2026-09-07

Authors: Gautam Bharti, Mayur Agnihotri

Institutions: Keysight Technologies (United Kingdom)