{
  "github_samples": {
    "bundle_stamped_at": "2026-07-28T19:00:00Z",
    "code_redistributed": false,
    "samples": [
      {
        "commit": "eb088dfe9d854dab6453a8d4ae5871a5ced20974",
        "license": "MIT",
        "patterns_used": [
          "stdio transport",
          "tool allowlists",
          "read-only annotations",
          "exact tool-name dispatch"
        ],
        "repository": "https://github.com/github/github-mcp-server"
      },
      {
        "commit": "0b5cc0f6a9ba326d7982b4f03ea7da83bf7817a2",
        "license": "see upstream LICENSE",
        "patterns_used": [
          "server metadata",
          "source repository linkage",
          "immutable versions",
          "read-only discovery API"
        ],
        "repository": "https://github.com/modelcontextprotocol/registry"
      },
      {
        "commit": "d31124c982401739917fd817c2a59db344529c16",
        "license": "see upstream LICENSE",
        "patterns_used": [
          "independent server processes",
          "controlled tool access",
          "structured tool contracts"
        ],
        "repository": "https://github.com/modelcontextprotocol/servers"
      },
      {
        "commit": "cd24afe0dcafc8c396e46d3d0d172a43a7e5e5e8",
        "license": "MIT",
        "patterns_used": [
          "CRM object search",
          "tenant-scoped records",
          "read/write contract separation"
        ],
        "repository": "https://github.com/advancedcommunities/salesforce-mcp-server",
        "version": "1.6.6"
      }
    ],
    "schema_version": 1
  },
  "live_web_snapshot": {
    "bundle_stamped_at": "2026-07-28T19:00:00Z",
    "limitations": [
      "Smithery performance counters are a point-in-time public-page snapshot.",
      "The authenticated Smithery registry API was not called because no key was present.",
      "Prices and model aliases can change; refresh before a paid live evaluation."
    ],
    "model_catalog": [
      {
        "model_id": "claude-sonnet-5",
        "pricing_note": "introductory through 2026-08-31",
        "pricing_usd_per_million": {
          "input": 2,
          "output": 10
        },
        "provider": "Anthropic",
        "source_id": "src-anthropic-sonnet-5",
        "tool_use": true
      },
      {
        "context_tokens": 1000000,
        "max_output_tokens": 384000,
        "model_id": "deepseek-v4-flash",
        "pricing_usd_per_million": {
          "cache_miss_input": 0.14,
          "output": 0.28
        },
        "provider": "DeepSeek",
        "source_id": "src-deepseek-v4-flash",
        "tool_use": true
      },
      {
        "context_tokens": 1050000,
        "max_output_tokens": 128000,
        "mcp": true,
        "model_id": "gpt-5.6-luna",
        "pricing_usd_per_million": {
          "input": 1,
          "output": 6
        },
        "provider": "OpenAI",
        "source_id": "src-openai-gpt-5-6-luna",
        "tool_use": true
      }
    ],
    "schema_version": 1,
    "smithery_public_pages": [
      {
        "latency_p50_ms": 73,
        "observed_tool_calls": 6427,
        "qualified_name": "github",
        "score": 80,
        "source_id": "src-smithery-github",
        "uptime_30d_percent": 100
      },
      {
        "latency_p50_ms": 26,
        "observed_tool_calls": 11587,
        "qualified_name": "slack",
        "score": 74,
        "source_id": "src-smithery-slack",
        "uptime_30d_percent": 100
      },
      {
        "latency_p50_ms": 145,
        "observed_tool_calls": 2,
        "qualified_name": "stripe",
        "score": 64,
        "source_id": "src-smithery-stripe",
        "uptime_30d_percent": 100
      }
    ]
  },
  "official_mcp_registry_snapshot": {
    "bundle_stamped_at": "2026-07-28T19:00:00Z",
    "endpoint": "https://registry.modelcontextprotocol.io/v0.1/servers",
    "records": [
      {
        "name": "ai.smithery/smithery-ai-github",
        "query": "github",
        "repository": "https://github.com/smithery-ai/mcp-servers",
        "status": "active",
        "version": "1.0.0"
      },
      {
        "name": "ai.cirra/salesforce-mcp",
        "query": "salesforce",
        "repository": "https://github.com/cirra-ai/mcp-server",
        "status": "active",
        "version": "1.0.0"
      },
      {
        "name": "com.stripe/mcp",
        "query": "stripe",
        "repository": "https://github.com/stripe/agent-toolkit",
        "status": "active",
        "version": "0.2.4"
      },
      {
        "name": "ai.smithery/smithery-ai-slack",
        "query": "slack",
        "repository": "https://github.com/smithery-ai/mcp-servers",
        "status": "active",
        "version": "1.0.0"
      },
      {
        "name": "io.github.CSOAI-ORG/customer-support-ai-mcp",
        "query": "support",
        "repository": "https://github.com/CSOAI-ORG/customer-support-ai-mcp",
        "status": "active",
        "version": "1.0.1"
      }
    ],
    "retrieval": "unauthenticated live REST queries with search and limit parameters",
    "schema_version": 1
  },
  "queries": [
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "verify requested Anthropic model identity",
      "query": "site:docs.anthropic.com \"Sonnet 5\" model",
      "query_id": "q001",
      "selected_source_ids": [
        "src-anthropic-sonnet-5"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "verify requested OpenAI model identity and tool support",
      "query": "site:platform.openai.com/docs/models \"GPT-5.6 Luna\"",
      "query_id": "q002",
      "selected_source_ids": [
        "src-openai-gpt-5-6-luna"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "verify requested DeepSeek model id and API shape",
      "query": "site:api-docs.deepseek.com \"deepseek-v4-flash\"",
      "query_id": "q003",
      "selected_source_ids": [
        "src-deepseek-v4-flash"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "pin protocol behavior",
      "query": "MCP 2025-11-25 tools server JSON-RPC specification",
      "query_id": "q004",
      "selected_source_ids": [
        "src-mcp-tools-spec"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "capture registry API contract",
      "query": "official MCP Registry REST API v0.1 aggregators",
      "query_id": "q005",
      "selected_source_ids": [
        "src-mcp-registry-aggregators"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "identify Smithery structured search endpoint and auth",
      "query": "site:smithery.ai/docs registry search servers API",
      "query_id": "q006",
      "selected_source_ids": [
        "src-smithery-search-docs"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground engineering tool surface",
      "query": "site:smithery.ai/servers GitHub MCP",
      "query_id": "q007",
      "selected_source_ids": [
        "src-smithery-github"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground collaboration interaction patterns",
      "query": "site:smithery.ai/servers Slack MCP",
      "query_id": "q008",
      "selected_source_ids": [
        "src-smithery-slack"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground billing tool patterns",
      "query": "site:smithery.ai/servers Stripe MCP",
      "query_id": "q009",
      "selected_source_ids": [
        "src-smithery-stripe"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "find primary sample implementation",
      "query": "GitHub official MCP server repository toolsets stdio",
      "query_id": "q010",
      "selected_source_ids": [
        "src-github-mcp-server"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground environment-factory architecture",
      "query": "arXiv Agent-World 2604.18292",
      "query_id": "q011",
      "selected_source_ids": [
        "src-agent-world-paper"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground DAG and compiler checks",
      "query": "arXiv ScaleEnv tool dependency graph executable verification",
      "query_id": "q012",
      "selected_source_ids": [
        "src-scaleenv-paper"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "ground task diversity and evaluation design",
      "query": "arXiv Toolathlon long-horizon MCP execution verifier",
      "query_id": "q013",
      "selected_source_ids": [
        "src-toolathlon-paper"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "verify the bounded output parameter for the OpenAI live runner",
      "query": "site:platform.openai.com/docs/api-reference/chat/create max_completion_tokens GPT-5.6",
      "query_id": "q014",
      "selected_source_ids": [
        "src-openai-chat-completions"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "prevent hidden reasoning from being persisted in live traces",
      "query": "site:api-docs.deepseek.com deepseek-v4-flash thinking disabled tool calls reasoning_content",
      "query_id": "q015",
      "selected_source_ids": [
        "src-deepseek-thinking-mode"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "define the official Salesforce CRM surface being emulated",
      "query": "site:developer.salesforce.com/docs/platform/hosted-mcp-servers SObject tools create read update search",
      "query_id": "q016",
      "selected_source_ids": [
        "src-salesforce-mcp",
        "src-salesforce-sobject-all-guide"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "define the official Zendesk ticket lifecycle being emulated",
      "query": "site:developer.zendesk.com/api-reference/ticketing/tickets status priority internal comments update ticket",
      "query_id": "q017",
      "selected_source_ids": [
        "src-zendesk-tickets-api"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "define the official Stripe MCP billing surface being emulated",
      "query": "site:docs.stripe.com/mcp list_invoices create_refund search_stripe_resources",
      "query_id": "q018",
      "selected_source_ids": [
        "src-stripe-mcp",
        "src-stripe-invoice-object"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "define the official GitHub engineering surface being emulated",
      "query": "site:docs.github.com GitHub MCP server repositories issues pull requests toolsets",
      "query_id": "q019",
      "selected_source_ids": [
        "src-github-mcp-server",
        "src-github-mcp-server"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "define the official Confluence knowledge surface being emulated",
      "query": "site:support.atlassian.com/atlassian-rovo-mcp-server supported tools Confluence search get update page",
      "query_id": "q020",
      "selected_source_ids": [
        "src-atlassian-rovo-supported-tools"
      ]
    },
    {
      "executed_at": "2026-07-28T19:00:00Z",
      "purpose": "compare vendor permission and audit requirements",
      "query": "enterprise MCP permissions OAuth least privilege audit logs Salesforce Stripe GitHub Atlassian",
      "query_id": "q021",
      "selected_source_ids": [
        "src-salesforce-mcp",
        "src-stripe-mcp",
        "src-github-mcp-server",
        "src-atlassian-rovo-supported-tools"
      ]
    }
  ],
  "research_trace": [
    {
      "action": "verify_model_names",
      "query_ids": [
        "q001",
        "q002",
        "q003"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "all three requested API model ids were found in provider-primary sources",
      "step": 1
    },
    {
      "action": "pin_protocol",
      "query_ids": [
        "q004"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "selected MCP revision 2025-11-25 and JSON-RPC stdio behavior",
      "step": 2
    },
    {
      "action": "sample_registries",
      "query_ids": [
        "q005",
        "q006",
        "q007",
        "q008",
        "q009"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "captured official registry REST records and Smithery public pages; recorded Smithery API authentication boundary",
      "step": 3
    },
    {
      "action": "pin_code_provenance",
      "query_ids": [
        "q010"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "recorded four upstream repository HEAD/pinned commit ids without copying code",
      "step": 4
    },
    {
      "action": "synthesize_research_design",
      "query_ids": [
        "q011",
        "q012",
        "q013"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "selected 100 diverse tasks, executable state verifiers, strict DAG paths, deterministic seeds, and diagnosis-ready traces",
      "step": 5
    },
    {
      "action": "apply_truthfulness_gate",
      "query_ids": [],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "no provider keys were present; model-target traces are labeled deterministic fixtures and an explicitly authorized, metered live runner with an optional spend ceiling is supplied",
      "step": 6
    },
    {
      "action": "harden_live_trace_privacy_and_bounds",
      "query_ids": [
        "q014",
        "q015"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "used max_completion_tokens for GPT-5.6 Luna, disabled DeepSeek thinking mode, and omitted provider-only reasoning fields",
      "step": 7
    },
    {
      "action": "define_mocked_product_requirements",
      "query_ids": [
        "q016",
        "q017",
        "q018",
        "q019",
        "q020",
        "q021"
      ],
      "recorded_at": "2026-07-28T19:00:00Z",
      "result": "mapped every mock server and tool to vendor-primary product documentation, then recorded permissions, state transitions, acceptance criteria, and intentional parity gaps",
      "step": 8
    }
  ],
  "smithery_registry_snapshot": {
    "bundle_stamped_at": "2026-07-28T19:00:00Z",
    "claim_boundary": "These records came from publicly indexed Smithery pages, not the authenticated registry API. They are live-search evidence, not a full registry dump.",
    "public_page_records": [
      {
        "latency_p50_ms": 73,
        "observed_tool_calls": 6427,
        "qualified_name": "github",
        "score": 80,
        "source_id": "src-smithery-github",
        "uptime_30d_percent": 100
      },
      {
        "latency_p50_ms": 26,
        "observed_tool_calls": 11587,
        "qualified_name": "slack",
        "score": 74,
        "source_id": "src-smithery-slack",
        "uptime_30d_percent": 100
      },
      {
        "latency_p50_ms": 145,
        "observed_tool_calls": 2,
        "qualified_name": "stripe",
        "score": 64,
        "source_id": "src-smithery-stripe",
        "uptime_30d_percent": 100
      }
    ],
    "schema_version": 1,
    "structured_api": {
      "observed": "HTTP 403 Forbidden on 2026-07-29 with the stored SMITHERY_API_KEY; api.smithery.ai/servers returned 403 as well. The public-page records below remain the only Smithery evidence in this bundle.",
      "required_env": "SMITHERY_API_KEY",
      "source_id": "src-smithery-search-docs",
      "status": "called_and_rejected",
      "url": "https://registry.smithery.ai/servers"
    }
  },
  "sources": [
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Pins the requested model identifier and motivates long-horizon, multi-tool, verifier-backed tasks.",
      "published_at": "2026-06-30",
      "publisher": "Anthropic",
      "record_sha256": "befac117400b4aef4709b747c06fddc991c5054997c472dc9b5241dda9004da6",
      "source_id": "src-anthropic-sonnet-5",
      "source_type": "model_launch_primary",
      "summary": "Anthropic identifies the API model as claude-sonnet-5 and positions it for agentic planning, tool use, coding, and knowledge work. The launch lists introductory pricing through August 31, 2026.",
      "title": "Introducing Claude Sonnet 5",
      "url": "https://www.anthropic.com/news/claude-sonnet-5"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Pins the API id and confirms that a native MCP/tool-use evaluation is within the documented capability surface.",
      "published_at": "2026-07-09",
      "publisher": "OpenAI",
      "record_sha256": "ebeeb50f9ceb0912329f95cb188c40e75630d20a9f89155649579f3771405884",
      "source_id": "src-openai-gpt-5-6-luna",
      "source_type": "model_documentation_primary",
      "summary": "OpenAI documents gpt-5.6-luna as a cost-sensitive GPT-5.6 tier with function calling and MCP support, a 1,050,000-token context window, and a 128,000-token maximum output.",
      "title": "GPT-5.6 Luna Model",
      "url": "https://developers.openai.com/api/docs/models/gpt-5.6-luna"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Pins the API id and OpenAI-compatible transport used by the live runner.",
      "published_at": "2026-04-24",
      "publisher": "DeepSeek",
      "record_sha256": "d3c505e9a74a412ae67fdb06ccd18ef6d5c77b81fe513961cf2e7fa44092f57a",
      "source_id": "src-deepseek-v4-flash",
      "source_type": "model_documentation_primary",
      "summary": "DeepSeek documents deepseek-v4-flash on its OpenAI-compatible API, with tool calls, a one-million-token context, and both thinking and non-thinking modes.",
      "title": "Models & Pricing — DeepSeek V4 Flash",
      "url": "https://api-docs.deepseek.com/quick_start/pricing/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Determines the GPT-5.6 Luna live runner's bounded output parameter while retaining the model's documented Chat Completions endpoint.",
      "published_at": null,
      "publisher": "OpenAI",
      "record_sha256": "c7f30df4a083b564c6d0fe49628029f78e652aca2b568b521c4b1531114c1c44",
      "source_id": "src-openai-chat-completions",
      "source_type": "api_reference_primary",
      "summary": "OpenAI's Chat Completions reference documents function tools and the max_completion_tokens output bound for current reasoning models.",
      "title": "Chat Completions API Reference",
      "url": "https://platform.openai.com/docs/api-reference/chat/create"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "The live evaluator explicitly disables thinking and strips any provider-only reasoning fields from durable traces.",
      "published_at": null,
      "publisher": "DeepSeek",
      "record_sha256": "fd2d2f29b9fd9e127db6503274d4a17f0c1892274fc67fde940cba42172ba21d",
      "source_id": "src-deepseek-thinking-mode",
      "source_type": "api_guide_primary",
      "summary": "DeepSeek documents that thinking defaults to enabled, emits reasoning_content, and can be explicitly disabled with the thinking toggle.",
      "title": "Thinking Mode",
      "url": "https://api-docs.deepseek.com/guides/thinking_mode"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Determines the five stdio servers' wire format, tool schemas, structured results, and isError behavior.",
      "published_at": "2025-11-25",
      "publisher": "Model Context Protocol",
      "record_sha256": "52a6e08cd15553df511ac0e44916481dbc0fca49361914814148b806fc63c415",
      "source_id": "src-mcp-tools-spec",
      "source_type": "protocol_specification_primary",
      "summary": "The specification defines tools/list and tools/call, JSON Schema input contracts, structuredContent, output schemas, annotations, and separate protocol versus tool-execution error handling.",
      "title": "MCP 2025-11-25 — Server Tools",
      "url": "https://modelcontextprotocol.io/specification/2025-11-25/server/tools"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the live official-registry snapshot and the composite registry provenance format.",
      "published_at": "2025-09-08",
      "publisher": "Model Context Protocol",
      "record_sha256": "61a0f206171fa5e669f98a5e9923aed034a5f111a5c59570ce2c0b1c1a89248f",
      "source_id": "src-mcp-registry-aggregators",
      "source_type": "registry_documentation_primary",
      "summary": "The official registry exposes an unauthenticated read-only REST API at /v0.1/servers with cursor pagination and standardized server metadata.",
      "title": "MCP Registry Aggregators",
      "url": "https://modelcontextprotocol.io/registry/registry-aggregators"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the authenticated structured-data boundary. With no key in this build session, public indexed server pages were used and labeled.",
      "published_at": null,
      "publisher": "Smithery",
      "record_sha256": "456bf9053fbe2fcc4bef0c43da81a31e13e55658c6ba2109aa62abe8ec398154",
      "source_id": "src-smithery-search-docs",
      "source_type": "registry_documentation_primary",
      "summary": "Smithery documents GET https://api.smithery.ai/servers and requires a bearer API key. Search supports free-text fields and pagination.",
      "title": "Registry: Search Servers",
      "url": "https://smithery.ai/docs/concepts/registry_search_servers"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the engineering mock's read/create/link/review/merge surface.",
      "published_at": null,
      "publisher": "Smithery",
      "record_sha256": "2a030d8dda56c180baeb55d389a845654f1db42ecfde3cecea81ee661382741d",
      "source_id": "src-smithery-github",
      "source_type": "registry_public_page",
      "summary": "The public page exposes GitHub repository, issue, pull-request, workflow, and search tool patterns plus usage and latency metadata.",
      "title": "GitHub — MCP",
      "url": "https://smithery.ai/servers/GitHub"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Informed the audit-timeline and internal-note interaction style, without copying Slack-specific implementation code.",
      "published_at": "2025-11-19",
      "publisher": "Smithery",
      "record_sha256": "3c4193d599c1ca4ebcfa51a730e70d752494ded4b29263231d8cb5040d912537",
      "source_id": "src-smithery-slack",
      "source_type": "registry_public_page",
      "summary": "The public page lists conversation search, history, thread, message, file, channel, and user patterns with observed call counts.",
      "title": "Slack — MCP",
      "url": "https://smithery.ai/servers/slack"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Combined with the official registry Stripe record to ground invoice, payment, hold, and refund task semantics.",
      "published_at": "2025-11-19",
      "publisher": "Smithery",
      "record_sha256": "4d468054072070f8834fa6202cc53fb6c3df5ab4adf43fd3888872413d3dfc3b",
      "source_id": "src-smithery-stripe",
      "source_type": "registry_public_page",
      "summary": "The public registry page identifies Stripe as an MCP integration and exposes its observed tool/usage metadata.",
      "title": "Stripe — MCP",
      "url": "https://smithery.ai/servers/stripe"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds server isolation, per-server allowlists, tool discovery, and the engineering tool vocabulary.",
      "published_at": null,
      "publisher": "GitHub",
      "record_sha256": "74ec45600b81acd9dd529a444903b87b019b7f264a612472934c5fc1d532878b",
      "source_id": "src-github-mcp-server",
      "source_type": "github_repository_primary",
      "summary": "GitHub's MIT-licensed server documents stdio operation, selectable toolsets, individual tool allowlists, read-only mode, and exact tool names.",
      "title": "GitHub's official MCP Server",
      "url": "https://github.com/github/github-mcp-server"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the composite registry snapshot and source-admission fields.",
      "published_at": null,
      "publisher": "MCP contributors",
      "record_sha256": "629ec1d27ea9cb094ebff804a896457742d79404d9fe34e6968502ff6b38dbb6",
      "source_id": "src-mcp-registry-code",
      "source_type": "github_repository_primary",
      "summary": "The open registry implementation defines server metadata, validation, namespace ownership, read APIs, and publisher workflows.",
      "title": "modelcontextprotocol/registry",
      "url": "https://github.com/modelcontextprotocol/registry"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supports the decision to ship independent stdio servers with a separate composite host configuration.",
      "published_at": null,
      "publisher": "MCP contributors",
      "record_sha256": "254de529b4c4cc596adb152ac8790aeb35f4e58a9a493b0db49839c01d6ac1e4",
      "source_id": "src-mcp-reference-servers",
      "source_type": "github_repository_primary",
      "summary": "Reference servers demonstrate controlled model access to tools and data through SDK-based MCP implementations.",
      "title": "Model Context Protocol Servers",
      "url": "https://github.com/modelcontextprotocol/servers"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Defines the CRM mock's record-oriented read/write boundary, tenant permissions, audit expectations, and custom-tool positioning.",
      "published_at": "2026-04-15",
      "publisher": "Salesforce",
      "record_sha256": "4c38086c37d36a1fc7d1d4119872a8fb73c4bfd9a35118441fe7001027b67fb2",
      "source_id": "src-salesforce-mcp",
      "source_type": "product_documentation_primary",
      "summary": "Salesforce documents hosted MCP servers with per-user OAuth, field-level security, sharing-rule enforcement, SObject operations, custom tools, and product integrations.",
      "title": "Salesforce Hosted MCP Servers",
      "url": "https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Motivates real-source provenance, environment diversity, verifier execution, and diagnosis-driven curricula.",
      "published_at": "2026-04-20",
      "publisher": "arXiv",
      "record_sha256": "011869cf8e7b2506d86dfab47b7be3a48b936b81affe9518f54d04ce6292b25e",
      "source_id": "src-agent-world-paper",
      "source_type": "research_paper_primary",
      "summary": "Agent-World combines environment/task discovery with continuous self-evolving training over real-world tool ecosystems and executable tasks.",
      "title": "Agent-World: Scaling Real-World Environment Synthesis",
      "url": "https://arxiv.org/abs/2604.18292"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Motivates compiler checks, a strict function DAG, task paths, and executable action verification.",
      "published_at": "2026-02-06",
      "publisher": "arXiv",
      "record_sha256": "706af67d644a1e36d13be07f815d97c9b123fdb20c35353f9994288261204fb9",
      "source_id": "src-scaleenv-paper",
      "source_type": "research_paper_primary",
      "summary": "ScaleEnv synthesizes interactive environments and verifiable tasks, using procedural testing and tool dependency graph expansion.",
      "title": "ScaleEnv: Scaling Environment Synthesis from Scratch",
      "url": "https://arxiv.org/abs/2602.06820"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Motivates cross-app categories, seeded state, multi-step tasks, and per-task executable verifier results.",
      "published_at": "2025-10-29",
      "publisher": "arXiv / ICLR 2026",
      "record_sha256": "91fdbec1abec9ad2b29e906e9b5d2e8b02f0bcb7eb96d0cb2f1daf0ea52bd2df",
      "source_id": "src-toolathlon-paper",
      "source_type": "research_paper_primary",
      "summary": "Toolathlon evaluates long-horizon execution across realistic apps and hundreds of tools, with dedicated execution-based verifiers.",
      "title": "The Tool Decathlon",
      "url": "https://arxiv.org/abs/2510.25726"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Makes the endpoint cell in PRD section 2 traceable while marking it unretrieved. No crm mock behavior is derived from this probe.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "4d2fcc3fb7914a55639b0b37bb1e18cfd3b1522cc086e04fa6f3664a08793e3e",
      "source_id": "src-salesforce-sobject-all-endpoint",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body, so no endpoint content was retrieved. The address and its tool list are documented on Salesforce's SObject All guide page, retrieved separately.",
      "title": "Salesforce SObject All MCP endpoint (production)",
      "url": "https://api.salesforce.com/platform/mcp/v1/platform/sobject-all"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Makes the support endpoint cell in PRD sections 2 and 4.1 traceable as an auth-gated address that was probed but not read.",
      "published_at": null,
      "publisher": "Intercom",
      "record_sha256": "29da318e1e9ae471698e1fb397e481a9cd8900233a4ec28655ecbf54082d29ae",
      "source_id": "src-intercom-mcp-endpoint-us",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. Endpoint, transport and auth details come from Intercom's MCP guide, retrieved separately.",
      "title": "Intercom MCP endpoint (US)",
      "url": "https://mcp.intercom.com/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the second regional endpoint cited in PRD sections 2 and 4.1 with the same unretrieved status as its US counterpart.",
      "published_at": null,
      "publisher": "Intercom",
      "record_sha256": "e689e4c9044b96d317d5fe7ca71792d0ae39f62f7749d068fb76ada883077007",
      "source_id": "src-intercom-mcp-endpoint-eu",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The EU regional address is documented in Intercom's MCP guide, retrieved separately.",
      "title": "Intercom MCP endpoint (EU)",
      "url": "https://mcp.eu.intercom.com/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Makes the billing endpoint cell in PRD sections 2 and 5.1 traceable without claiming any endpoint content was read.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "5b5be8b1a917607554c69abf630f1f11905aba6cba101e8bc813da1ccbdb0c1a",
      "source_id": "src-stripe-mcp-endpoint",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The endpoint, its auth options and its tool list come from Stripe's MCP documentation page, retrieved separately.",
      "title": "Stripe remote MCP endpoint",
      "url": "https://mcp.stripe.com"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Makes the engineering endpoint cell in PRD sections 2 and 6.1 traceable while marking it unretrieved.",
      "published_at": null,
      "publisher": "GitHub",
      "record_sha256": "66ebef372cb716475de90628f64d986fc96cc40c7103030100448ebe018fcead",
      "source_id": "src-github-mcp-remote-endpoint",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The endpoint and its authentication model come from the github/github-mcp-server repository, retrieved separately.",
      "title": "GitHub remote MCP endpoint",
      "url": "https://api.githubcopilot.com/mcp/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Makes the knowledge endpoint cell in PRD sections 2 and 7.1 traceable while marking it unretrieved.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "cba61ec75433041b501ff5165b15dc092701b5f1f86d83cfb9606d3188e0d910",
      "source_id": "src-atlassian-mcp-endpoint-authv2",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The address and its recommended status come from the Atlassian Rovo MCP Server repository, retrieved separately.",
      "title": "Atlassian remote MCP endpoint (authv2)",
      "url": "https://mcp.atlassian.com/v1/mcp/authv2"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds PRD section 3.1 and the auth row of section 3.4, where the crm mock declares no credentials, no tenant and no permission model at all.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "213743f5d314bb6c40d528841e285830be8902f41276083f7a6f2351a81bc08d",
      "source_id": "src-salesforce-hosted-mcp-overview",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "Salesforce documents a family of first-party hosted MCP servers that let a compatible AI client connect to an org and act on behalf of authorized users, using per-user OAuth 2.0 with PKCE, with field-level security and sharing rules applied to tool calls. Claude, ChatGPT, Cursor and Postman are named as clients.",
      "title": "Salesforce Hosted MCP Servers",
      "url": "https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the server catalogue in PRD section 3.1 and the omitted-delete row of section 3.3: Salesforce ships an entire SObject Deletes server, and this world has no delete tool anywhere.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "151a78d66feb7fdebf0952ec5d5104f099c4cd2f3580f708a562aefc8e2d3b92",
      "source_id": "src-salesforce-hosted-mcp-servers-reference",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "The reference enumerates seven standard servers: SObject All, SObject Reads, SObject Mutations, SObject Deletes, Data 360, Headless 360 (Beta) and Tableau Next. It states that field-level security, object permissions and sharing rules apply to every tool call.",
      "title": "Standard MCP Servers Reference",
      "url": "https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/servers-reference.html"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the sandbox endpoint cited in PRD section 3.1 as probed but unread.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "5d31a2dc614114ff8bc41cbb81e1640ef351ee98a07e6eee4f1c54ab9fbeb478",
      "source_id": "src-salesforce-sobject-all-sandbox-endpoint",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The sandbox address is documented on Salesforce's SObject All guide page, retrieved separately.",
      "title": "Salesforce SObject All MCP endpoint (sandbox)",
      "url": "https://api.salesforce.com/platform/mcp/v1/sandbox/platform/sobject-all"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the schema-generic versus operation-specific contrast in PRD section 3.1 and every row of the section 3.3 tool mapping. This retrieval names whoami where PRD sections 3.1 and 3.3 say getAuthenticatedUser; the PRD text was left unchanged for a human to reconcile.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "d532e2b9ad56ac31f06acf29bb0dbdd8597b14538896164f20f04a5c47528a04",
      "source_id": "src-salesforce-sobject-all-guide",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "The guide documents the production and sandbox server addresses and eleven tools: getObjectSchema, soql_query, find, whoami, getRecentRecords, getRelatedRecords, createSobjectRecord, updateSobjectRecord, updateRelatedRecord, deleteSobjectRecord and deleteRelatedRecord. The surface is schema-generic: one parameterised create and update plus SOQL, rather than named per-object verbs.",
      "title": "SObject All",
      "url": "https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/sobject-all.html"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Cited in PRD section 3.1 only so a reader does not conflate Salesforce's developer-tooling server with the hosted CRM data server the crm mock imitates.",
      "published_at": null,
      "publisher": "Salesforce CLI",
      "record_sha256": "b2e94fb1912a633d30c786b5d4909ebe2a8e389011ac0e7023df554ceb2eba48",
      "source_id": "src-salesforce-dx-mcp-server",
      "source_type": "github_repository_primary",
      "summary": "An Apache-2.0 developer-tooling MCP server maintained by the salesforcecli organisation, documenting 60+ tools across toolsets including metadata, orgs, code-analysis, lwc-experts, testing, data and devops, reaching orgs pre-authorised through the Salesforce CLI.",
      "title": "Salesforce DX MCP Server",
      "url": "https://github.com/salesforcecli/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supports the secondary-vendor status in PRD section 3.1 and the section 9 limitation that no HubSpot tool name appears anywhere in this bundle.",
      "published_at": null,
      "publisher": "HubSpot",
      "record_sha256": "999a1e6af42a3671c3caced15137caaec339dcf51e3f6779f6a81d9fc03c9de7",
      "source_id": "src-hubspot-mcp",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "HubSpot documents a remote MCP server at mcp.hubspot.com authenticated with OAuth 2.0 through a user-level app and its scopes, plus a local CLI-based developer server. It lists accessible CRM objects and engagements but does not enumerate individual tool names.",
      "title": "HubSpot MCP",
      "url": "https://developers.hubspot.com/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the limitation stated in PRD sections 3.2 and 9: the real-object field column of the crm mapping is our design target, not a verified Salesforce quotation.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "252afc1c8796b10dec31a763e06dec84171612f9eb2735ecc197f036314c0104",
      "source_id": "src-salesforce-object-account",
      "source_type": "retrieval_limitation",
      "summary": "The fetch returned the object-reference navigation and the alphabetical standard-object index only. Account appears in that index, but the field-level tables are client-rendered and were not retrieved.",
      "title": "Salesforce Object Reference — Account",
      "url": "https://developer.salesforce.com/docs/atlas.en-us.object_reference.meta/object_reference/sforce_api_objects_account.htm"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supports the same limitation in PRD sections 3.2 and 9 for the ticket-side object mapping.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "6515689d78b485e453bb35b333897b32f4820dd92f522ffd8b33f80504bb626e",
      "source_id": "src-salesforce-object-case",
      "source_type": "retrieval_limitation",
      "summary": "The fetch returned navigation and the alphabetical standard-object index only. Case appears in that index; no field names, types or descriptions were retrieved.",
      "title": "Salesforce Object Reference — Case",
      "url": "https://developer.salesforce.com/docs/atlas.en-us.object_reference.meta/object_reference/sforce_api_objects_case.htm"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the Salesforce pagination row of PRD section 3.4, against which the mock's limit-only truncation, with no cursor and no done flag, is measured.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "d5258fd1f634c7440a3e47e8e0c71149a7bea1ca31b0e0ea1373b1235b47d1cf",
      "source_id": "src-salesforce-rest-query",
      "source_type": "api_reference_primary",
      "summary": "The Query resource returns totalSize, done and records, plus nextRecordsUrl while more results remain. Clients follow the query-locator path until done is true.",
      "title": "Execute a SOQL Query",
      "url": "https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/dome_query.htm"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the Salesforce rate-limit row of PRD section 3.4 and the section 8 statement that this world has no quota, no concurrency cap and no 429 equivalent.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "a60257acd90112f9814380d4d2a0ed5dedc728743358761befcdf3167b1312ad",
      "source_id": "src-salesforce-api-limits",
      "source_type": "api_reference_primary",
      "summary": "The cheat sheet documents 24-hour API allocations by edition — Developer Edition 15,000; Enterprise and Professional 100,000 plus per-license calls; Unlimited and Performance 100,000 plus larger per-license calls; Full Sandbox 5,000,000 — concurrency limits for calls of 20 seconds or longer (5 for Developer and Trial, 25 for production and sandboxes), and the REQUEST_LIMIT_EXCEEDED, QUERY_TIMEOUT and REQUEST_RUNNING_TOO_LONG conditions.",
      "title": "API Request Limits and Allocations",
      "url": "https://developer.salesforce.com/docs/atlas.en-us.salesforce_app_limits_cheatsheet.meta/salesforce_app_limits_cheatsheet/salesforce_app_limits_platform_api.htm"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the Salesforce error row of PRD section 3.4 and the section 8 contrast with this world's single isError channel and six-code vocabulary.",
      "published_at": null,
      "publisher": "Salesforce",
      "record_sha256": "35003389082fe11a41add54942a0136ecb2c4364b90f4caf69d794fc989fa6b4",
      "source_id": "src-salesforce-rest-error-codes",
      "source_type": "api_reference_primary",
      "summary": "The reference documents 200, 201 and 204 successes, client errors including 400, 401, 403, 404, 405, 409 and 410, server errors 500, 502 and 503, and an error body carrying message, errorCode (for example MALFORMED_ID or NOT_FOUND) and an optional fields array.",
      "title": "Status Codes and Error Responses",
      "url": "https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/errorcodes.htm"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Establishes the status fact in PRD section 4.1 that Zendesk is an MCP client rather than an MCP vendor, which is why the support mock is modeled on Zendesk's REST API instead.",
      "published_at": null,
      "publisher": "Zendesk",
      "record_sha256": "8f5adef85d2e95b72482249c18d57020b50f311d7f03dbf294c44d2b5cfa0c28",
      "source_id": "src-zendesk-mcp-support-article",
      "source_type": "vendor_support_article_primary",
      "summary": "The article describes admins connecting Zendesk to external MCP servers and using the discovered tools as steps in action flows, naming Asana, Stripe and GitHub as example servers Zendesk consumes. It describes no Zendesk-hosted MCP server and labels the capability an early access program.",
      "title": "Connecting to MCP servers and using MCP tools in action flows (EAP)",
      "url": "https://support.zendesk.com/hc/en-us/articles/10497779528730"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the community tool vocabulary compared against the support mock in PRD section 4.3, and is labeled community-maintained wherever cited.",
      "published_at": null,
      "publisher": "reminia (community)",
      "record_sha256": "8464609ba2145d86024cbeb419c6e6becc74b995d2dd4e9b1ef37610de67e8c1",
      "source_id": "src-zendesk-community-mcp-server",
      "source_type": "github_repository_primary",
      "summary": "An Apache-2.0 community project, not a Zendesk product, running over stdio with credentials supplied from an environment file. It exposes get_tickets, get_ticket, get_ticket_comments, create_ticket_comment, create_ticket and update_ticket, a zendesk://knowledge-base resource, and the analyze-ticket and draft-ticket-response prompts.",
      "title": "reminia/zendesk-mcp-server",
      "url": "https://github.com/reminia/zendesk-mcp-server"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Provides the vendor-official support MCP comparison in PRD sections 4.1 and 4.3, including that its only write surface is Help Center articles.",
      "published_at": null,
      "publisher": "Intercom",
      "record_sha256": "e206229d1dcdbec6566f25dde967b4a28241feac007c5f914e6dc3eb703b2ac1",
      "source_id": "src-intercom-mcp",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "Intercom documents a first-party MCP server on US and EU endpoints, recommending Streamable HTTP with legacy SSE deprecated, authenticated by OAuth or a bearer token. It lists thirteen tools and is read-focused: only create_article and update_article write, and AU-hosted workspaces are not supported.",
      "title": "Model Context Protocol (MCP) — Intercom",
      "url": "https://developers.intercom.com/docs/guides/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the ticket object and pagination rows of PRD sections 4.2 and 4.4, and the boundary that four of six Zendesk statuses and the urgent priority do not exist in this world.",
      "published_at": null,
      "publisher": "Zendesk",
      "record_sha256": "627db8377aa5c6dfb060f65af036f243df0046884d962da4ecb257663f0d87aa",
      "source_id": "src-zendesk-tickets-api",
      "source_type": "api_reference_primary",
      "summary": "The Ticket reference documents statuses new, open, pending, hold, solved and closed, priorities urgent, high, normal and low, and fields including requester_id, assignee_id, organization_id, group_id, type, tags, custom_fields and collaborator ids. Listing supports cursor pagination with page[size] and page[after] or offset pagination, at a maximum of 100 records per page.",
      "title": "Tickets",
      "url": "https://developer.zendesk.com/api-reference/ticketing/tickets/tickets/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the auth row of PRD section 4.4 and the section 8 statement that no credential, scope or impersonation surface exists here, so least-privilege behavior cannot be exercised.",
      "published_at": null,
      "publisher": "Zendesk",
      "record_sha256": "31bf81d55d6de6d006fd8928995fb4d845848e4c62e888c951c18a350a330736",
      "source_id": "src-zendesk-security-and-auth",
      "source_type": "api_reference_primary",
      "summary": "Zendesk documents API-token basic auth in the form {email_address}/token:{api_token}, OAuth access tokens sent as a bearer header with a 184-character maximum, and global OAuth tokens for apps distributed to multiple customers. It warns that API tokens can impersonate anyone in the account, including admins.",
      "title": "Security and authentication",
      "url": "https://developer.zendesk.com/api-reference/introduction/security-and-auth/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the rate-limit row of PRD section 4.4 and the section 8 statement that no 429 and no Retry-After exists anywhere in this world.",
      "published_at": null,
      "publisher": "Zendesk",
      "record_sha256": "bf5bb7eb4b4f487495ec3eacf8b01b467dc1196560ee9dfad1a1f19c75e7036f",
      "source_id": "src-zendesk-rate-limits",
      "source_type": "api_reference_primary",
      "summary": "Zendesk Suite plans are documented at 200 to 2,500 requests per minute by tier and Zendesk Support at 10 to 700, with the High Volume API add-on raising a qualifying plan to 2,500 rather than adding to it, plus an account-wide safety threshold of 100,000 requests per minute. Exceeding a limit returns HTTP 429 with rate-limit and Retry-After headers.",
      "title": "Rate limits — Zendesk",
      "url": "https://developer.zendesk.com/api-reference/introduction/rate-limits/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the generic-gateway versus operation-specific contrast in PRD section 5.1 and the auth row of section 5.4. The retrieved page states that many API methods are exposed through the two generic tools; the '100+ API methods' figure in PRD section 5.1 was not confirmed by this retrieval and was left for a human to reconcile.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "c8cc3138e11660e9540c77e551fc7f5c3830b70ee3349a5509dda393fb040111",
      "source_id": "src-stripe-mcp",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "Stripe documents a remote MCP server at mcp.stripe.com, preferring OAuth for interactive clients while allowing autonomous agents to present a bearer secret key, strongly recommending restricted keys, and requiring a Stripe-Account header for connected accounts. Much of the API is reached through the generic stripe_api_read and stripe_api_write tools rather than as individual tools; create_refund is one of the few operation-specific ones.",
      "title": "Model Context Protocol (MCP) — Stripe",
      "url": "https://docs.stripe.com/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the retrieval failure stated in PRD sections 5.1 and 9, which is why the invented hold and release workflow in the billing mock claims no upstream source.",
      "published_at": null,
      "publisher": "Oracle NetSuite",
      "record_sha256": "fbbda749c29c6dbaf04fd4fa92f5ece4593671d7399bec5a4c637d0f4560eea3",
      "source_id": "src-netsuite-mcp-article",
      "source_type": "retrieval_limitation",
      "summary": "The fetch returned HTTP 403 Forbidden with no body. No NetSuite content was retrieved, and no claim about a NetSuite first-party MCP surface is made anywhere in this bundle.",
      "title": "NetSuite article on the Model Context Protocol",
      "url": "https://www.netsuite.com/portal/resource/articles/artificial-intelligence/model-context-protocol-mcp.shtml"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supports PRD sections 5.1 and 9: Oracle's published MCP repository does not cover NetSuite, so no NetSuite fidelity is claimed for the billing mock.",
      "published_at": null,
      "publisher": "Oracle",
      "record_sha256": "d5e77b34807d49e311c99a6b55be63058f9f8853fb39bbc6039ea3d3042c5d0f",
      "source_id": "src-oracle-mcp-repository",
      "source_type": "github_repository_primary",
      "summary": "The repository documents OCI and database servers, including oci-cloud-mcp-server, oci-api-mcp-server, oci-compute-mcp-server, oci-identity-mcp-server and dbtools-mcp-server. NetSuite is not mentioned in the content retrieved.",
      "title": "oracle/mcp",
      "url": "https://github.com/oracle/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the invoice mapping in PRD section 5.2, including that our on_hold status does not exist upstream and that our single floating-point amount with no currency field diverges from Stripe's minor-unit model.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "83d5faff1112c56e5eece9d5230d61571b88421336ac9c9bdc5f13ea4db7c595",
      "source_id": "src-stripe-invoice-object",
      "source_type": "api_reference_primary",
      "summary": "The Invoice object documents statuses draft, open, paid, uncollectible and void, integer amounts in the smallest currency unit across amount_due, amount_paid, amount_remaining, amount_overpaid, subtotal and total, a currency field, and auto_advance as the only control that stops an invoice advancing on its own. There is no hold or pause status.",
      "title": "The Invoice object",
      "url": "https://docs.stripe.com/api/invoices/object"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the refund mapping in PRD sections 5.2 and 5.3: ours is synchronous, always approved, free-text reasoned, and attached to an invoice rather than to a charge or PaymentIntent.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "7cf739fd9318db6c77d4b82040b5dac3ebf08b86746b23dad461d6019acf0426",
      "source_id": "src-stripe-refund-object",
      "source_type": "api_reference_primary",
      "summary": "The Refund object documents statuses pending, requires_action, succeeded, failed and canceled, reasons duplicate, fraudulent, requested_by_customer and the Stripe-generated expired_uncaptured_charge, and attachment to a charge or a payment_intent.",
      "title": "The Refund object",
      "url": "https://docs.stripe.com/api/refunds/object"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the pagination row of PRD section 5.4 and the section 8 statement that our tools truncate without a cursor or a has_more signal.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "b482e068bc20633fc986bd68673c040cf7864231803ac69acf25bf579d509d6d",
      "source_id": "src-stripe-pagination",
      "source_type": "api_reference_primary",
      "summary": "List endpoints take limit with a default of 10 and a range of 1 to 100, plus mutually exclusive starting_after and ending_before cursors, and return an object of type list with url, has_more and data.",
      "title": "Pagination",
      "url": "https://docs.stripe.com/api/pagination"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the rate-limit row of PRD section 5.4 and the section 8 comparison of per-second, per-minute and per-hour vendor limits against a world with none.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "a05eb72109c05de070695ef44530b1dd746bc337c842d29efc66be8cf4d484fd",
      "source_id": "src-stripe-rate-limits",
      "source_type": "api_reference_primary",
      "summary": "Stripe documents 100 requests per second in live mode, 25 in sandbox/test mode, and typically 25 per second per endpoint, returning HTTP 429 with a Stripe-Rate-Limited-Reason header whose values include global-rate, endpoint-rate, global-concurrency, endpoint-concurrency and resource-specific. Read requests carry allocation limits; write requests do not.",
      "title": "Rate limits — Stripe",
      "url": "https://docs.stripe.com/rate-limits"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the error and idempotency rows of PRD sections 5.4 and 8, against which this world's six codes, absent param and doc_url pointers, and missing idempotency keys are stated.",
      "published_at": null,
      "publisher": "Stripe",
      "record_sha256": "fa4941aa3060a0b21497eb5af7ce149ace4899ffa19673da1f2b0b6adf6f9ecf",
      "source_id": "src-stripe-errors",
      "source_type": "api_reference_primary",
      "summary": "The reference documents 400, 401, 402, 403, 404, 409 idempotency conflict, 424, 429 and 5xx statuses, and an error object with type values api_error, card_error, idempotency_error and invalid_request_error alongside message, code, param, decline_code, advice_code, charge, doc_url and request_log_url.",
      "title": "Errors",
      "url": "https://docs.stripe.com/api/errors"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the pull-request mapping in PRD section 6.2 and the pagination row of section 6.4, including that our three-value status enum with review_requested is not GitHub's model and that our caller supplies the merge SHA.",
      "published_at": null,
      "publisher": "GitHub",
      "record_sha256": "a976fe023502194e0999864cfb4644790c5da5606481c18389270f93afec5933",
      "source_id": "src-github-rest-pulls",
      "source_type": "api_reference_primary",
      "summary": "Pull requests carry state open or closed with a separate merged boolean and server-computed mergeable and mergeable_state, an array of requested_reviewers, head and base refs, and a merge_commit_sha whose meaning depends on the merge method. Listing uses per_page with a default of 30 and a maximum of 100, plus page, and filters state, sort, direction, head and base.",
      "title": "REST API endpoints for pull requests",
      "url": "https://docs.github.com/en/rest/pulls/pulls"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the issue mapping in PRD section 6.2, including that our priority column is ours and that our disjoint issues and pull_requests tables do not reproduce GitHub's identity overlap.",
      "published_at": null,
      "publisher": "GitHub",
      "record_sha256": "0f43a60891d570f6716cd8be6bcb18c02b98bdd47ac3d25aefe99e3ec00a722d",
      "source_id": "src-github-rest-issues",
      "source_type": "api_reference_primary",
      "summary": "Issues carry state open or closed with labels, assignees, body, milestone and state_reason, and no native priority field. The reference states that the REST API considers every pull request an issue and that issue endpoints may return pull requests too.",
      "title": "REST API endpoints for issues",
      "url": "https://docs.github.com/en/rest/issues/issues"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the rate-limit row of PRD section 6.4 and the section 8 statement that neither primary nor secondary limits exist in this world.",
      "published_at": null,
      "publisher": "GitHub",
      "record_sha256": "208d9893bf1d9ef8c7bee19a76104a930465a958e0cdee634a32154770a08dd6",
      "source_id": "src-github-rest-rate-limits",
      "source_type": "api_reference_primary",
      "summary": "GitHub documents 60 requests per hour unauthenticated, 5,000 authenticated and 15,000 for Enterprise Cloud apps, with x-ratelimit-limit, x-ratelimit-remaining, x-ratelimit-used and x-ratelimit-reset headers, and 403 or 429 on exceeding a limit. Secondary limits cover 100 concurrent requests, 900 points per minute per endpoint, CPU time and content creation, with a retry-after header.",
      "title": "Rate limits for the REST API",
      "url": "https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the endpoint and auth statements in PRD section 7.1 and the section 9 note that Atlassian tool names had to come from the separate supported-tools page.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "4df8c8431620507ceda326ea9f251f28a273ec45bd9bc100cc54c2d7aae56d14",
      "source_id": "src-atlassian-mcp-server-repo",
      "source_type": "github_repository_primary",
      "summary": "The official remote MCP server repository documents the recommended /v1/mcp/authv2 endpoint alongside /v1/mcp and a legacy SSE address, over HTTPS, authenticated by OAuth 2.1 or API tokens. The README organises access by permission group rather than enumerating tool names, and tells clients to use maxResults or limit of 10 on all JQL and CQL searches.",
      "title": "Atlassian Rovo MCP Server",
      "url": "https://github.com/atlassian/atlassian-mcp-server"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Records the alternate endpoint cited in PRD section 7.1 as probed but unread.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "fbe31f6a7edf82559bf30d48ba38c8eb4e7457422fc1aabbc43c28ec3ce1053d",
      "source_id": "src-atlassian-mcp-endpoint",
      "source_type": "retrieval_limitation",
      "summary": "An unauthenticated GET returned HTTP 401 Unauthorized with no body. The address and its status relative to the authv2 endpoint come from the Atlassian Rovo MCP Server repository, retrieved separately.",
      "title": "Atlassian remote MCP endpoint",
      "url": "https://mcp.atlassian.com/v1/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the tool names in PRD section 7.1 and the mapping and omission rows of section 7.3, including that our knowledge server has no comment, space or hierarchy surface.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "54c2501064f7defe6f9625e4e6ce8b318f7cdd8253d9be8ef442b68f69966aaf",
      "source_id": "src-atlassian-rovo-supported-tools",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "The reference groups Confluence tools by permission scope: read_confluence covers getConfluencePage, getConfluencePageDescendants, getConfluencePageFooterComments, getConfluencePageInlineComments, getConfluenceCommentChildren, getConfluenceSpaces and getPagesInConfluenceSpace; write_confluence covers createConfluencePage, updateConfluencePage, createConfluenceFooterComment and createConfluenceInlineComment; search_confluence covers searchConfluenceUsingCql.",
      "title": "Supported tools — Atlassian Rovo MCP Server",
      "url": "https://support.atlassian.com/atlassian-rovo-mcp-server/docs/supported-tools/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supports the secondary-vendor status in PRD section 7.1. The retrieved page does state an OAuth connection method, which is narrower than PRD sections 7.1, 7.4 and 9, which say the auth method was not stated; the PRD text was left unchanged for a human to reconcile.",
      "published_at": null,
      "publisher": "Notion",
      "record_sha256": "9a3fe225d19592d555d10e77d7011255a2ca938ef3453eb794501d97cfb06692",
      "source_id": "src-notion-mcp",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "Notion describes Notion MCP as its hosted server giving AI tools secure access to a workspace, with one-click installation for supported tools. The retrieved page states no endpoint URL; it does describe connecting through OAuth.",
      "title": "Notion MCP",
      "url": "https://developers.notion.com/docs/mcp"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the Notion tool list in PRD section 7.1 and the statements in sections 7.3 and 7.5 that this world has no asynchronous task model and no cross-tool search.",
      "published_at": null,
      "publisher": "Notion",
      "record_sha256": "26e2ba6e1c253c70a75ff6f0699232dc9e15b28d71734cb0d21d256ef8538b44",
      "source_id": "src-notion-mcp-supported-tools",
      "source_type": "vendor_mcp_documentation_primary",
      "summary": "The page lists eighteen tools: notion-search, notion-fetch, notion-create-pages, notion-update-page, notion-move-pages, notion-duplicate-page, notion-create-database, notion-update-data-source, notion-create-view, notion-update-view, notion-query-data-sources, notion-query-database-view, notion-query-meeting-notes, notion-create-comment, notion-get-comments, notion-get-teams, notion-get-users and notion-get-async-task. Duplication completes asynchronously and is polled with notion-get-async-task, and search can span connected tools such as Slack, Google Drive and Jira.",
      "title": "Supported tools — Notion MCP",
      "url": "https://developers.notion.com/guides/mcp/mcp-supported-tools"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Grounds the document mapping in PRD section 7.2 and the auth and pagination rows of section 7.4, where our single flat document table and cursorless limit are contrasted with it.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "e1b31a4cd6adb85f09ff133749a304bd414ac58931d60e7095bfe993a4318d80",
      "source_id": "src-confluence-rest-v2-intro",
      "source_type": "api_reference_primary",
      "summary": "The v2 API models pages, blog posts, comments, attachments, spaces, folders, labels, versions, ancestors and descendants, tasks, whiteboards, custom content and permissions, authenticated by JWT or OAuth 2.0 for apps and basic auth for direct calls. Pagination is cursor-based with limit and cursor, a Link header carrying rel=next, and _links.next in the body.",
      "title": "The Confluence Cloud REST API",
      "url": "https://developer.atlassian.com/cloud/confluence/rest/v2/intro/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the points-based rate-limit row of PRD section 7.4 and the section 8 comparison of six different vendor limiting models against a world with none.",
      "published_at": null,
      "publisher": "Atlassian",
      "record_sha256": "c4daf553ade64f2ca64fc026ece87bb33e45122f3e463ca25a6ed1e7b9f9da62",
      "source_id": "src-confluence-rate-limiting",
      "source_type": "api_reference_primary",
      "summary": "Confluence Cloud charges one point per request plus one for core domain objects and two for identity and access objects on reads, with writes costing the base point. Tier 1 apps share a 65,000-point hourly pool; Tier 2 per-tenant pools are 100,000 plus 10 points per user for Standard, 130,000 plus 20 for Premium and 150,000 plus 30 for Enterprise, capped at 500,000 points per hour. Over budget returns HTTP 429 with Retry-After, RateLimit-Reason and X-RateLimit headers, and enforcement is stated to begin on 2 March 2026.",
      "title": "Rate limiting — Confluence Cloud",
      "url": "https://developer.atlassian.com/cloud/confluence/rate-limiting/"
    },
    {
      "bundle_stamped_at": "2026-07-28T19:00:00Z",
      "content_policy": "metadata and original summary only; full third-party text not redistributed",
      "design_use": "Supplies the Notion rate-limit and payload-limit rows of PRD section 7.4, against which our schema-only minLength and limit bounds are stated.",
      "published_at": null,
      "publisher": "Notion",
      "record_sha256": "f06a5efeb996dcd18814ac8a537c3ff04ae689b82437355b69c48ace2bcfd3dc",
      "source_id": "src-notion-request-limits",
      "source_type": "api_reference_primary",
      "summary": "Notion documents an average of three requests per second per connection with bursts, plus a workspace-level limit, returning HTTP 429 with the rate_limited code, a Retry-After header and additional_data.rate_limit_reason. Size limits include 1,000 block elements and 500 KB per request, 2,000-character rich text and URLs, 200-character emails and 100-element arrays, with violations returning HTTP 400 and validation_error.",
      "title": "Request limits",
      "url": "https://developers.notion.com/reference/request-limits"
    }
  ]
}
