Behaviour matches the manifest
The tools, scopes and destinations it declares are the ones it actually uses. Both directions count.
- Applies to
- agents, MCP servers, apps, templates
- Standard references
- none mapped
Why failing this one stops a sale
Almost nothing in this rubric is disqualifying. Most findings are information, published beside the badge and left to the buyer to weigh. This check is the exception, because software that does something other than what it declares is the shape of an attack rather than of untidy configuration, and no amount of disclosure makes that safe to sell.
Explainer · 2026-09-30
Behaviour matches the manifest: the one row that stops a sale, and why it is about honesty
Almost every finding here is information for a buyer to weigh. Software that does something other than what it declares is the exception, because that is the shape of an attack rather than of untidy work.
What this row checks
That the tools, scopes and destinations a listing declares are the ones it actually uses, in both directions. Doing something undeclared fails. So does declaring access it never uses, because an unused permission is a permission waiting for a reason.
What a mismatch looks like
One package removed from this catalogue described itself, in its own words, as a deliberately malicious server for testing. Its tool descriptions said one thing and its code another: a tool described as adding two numbers returned code, and others asked for API keys, passwords and card numbers. No description scanner would have flagged it, because the descriptions were bland. Holding the declaration against the behaviour is what catches it.
The quieter version is a rug pull: a server that declares one thing when it is approved and another on a later start or a later version. That is why a change in what a listing declares is treated here as a new product, not an update.
What can and cannot be checked
This row needs a manifest a maker has declared. A catalogue listing indexed from a public registry has none, so for it this row is not answerable, and the evidence map says so rather than showing a pass. It becomes answerable when a maker submits a listing with a manifest and it is run in the sandbox.
In the glossary: Capability manifest, Rug pull, Permission drift.
What this check has found
Nothing in the catalogue has raised a finding on this check. That is a fact about what has been tested so far rather than a guarantee about what is out there, and it is printed because a check that never fires is worth knowing about too.
Every listing in the catalogue shows its result on this check, with the findings summarised in public and the full report to whoever bought it. Open the catalogue.