Authority: Explanatory binding reference · Status: Protected E4.7 candidate, not deployed · Applies to: E4.7 · Verified against: current checkout · Source:internal/semanticmcp,internal/frontieragent, ADR 017 and ADR 020
Purpose
The frontier model is a consumer of TWIRX, not part of the protocol authority:twirx_universes distinguishes
queryable snapshot slices from described future universes; twirx_search
identifies executable templates; and twirx_describe returns a fully defaulted,
ready-to-run query. twirx_trace returns a compact source/proof projection by
default and requires an explicit full request for the larger proof-complete
form. The active runtime traces packet identifiers only, so the tool schema does
not advertise frame identifiers.
Task-ready agent context
twirx_context composes one exact typed query into a bounded LLM-facing
projection:
twirx_trace escalation.
The context is limited to 64 rows, 20 requested compact traces and 768 KiB of
encoded structured content.
The query-local semantic bindings report what the returned packets carry. They
are explicitly not normative concept definitions and cannot admit mappings.
Run the local MCP candidate
This example uses the admitted FUTO snapshot described in the quickstart. The snapshot is a generated artifact and must exist locally.twirx_query by placing the same bounded JSON query used by the Lab under
params.arguments.query. The result carries the snapshot, canonical query and
canonical result digests, native values, packet evidence identifiers, and an
execution plan. The plan must report zero origin-network requests for the
immutable runtime.
Fresh agent audit
On 2026-08-13, an MCP client exercised all nine tools against snapshotsha256:54739822257ef617b136454285a8fd47802f0960c7cf53a49abd2d5d1f1389c5.
The World Bank population template returned four source-bound rows after
scanning twenty packets and excluding five fixtures, with zero origin calls.
reports/e4-7-agent-context.md.
Frontier provider boundary
twirx-frontier-agent inspect validates the pinned provider configuration
without making a request. run additionally requires an explicit paid-execution
flag, an API key supplied only through the process environment, and a positive
USD ceiling. The candidate fixes the model, Responses endpoint, MCP endpoint,
answer schema, output bound, timeout, and one-repair limit.
The strict Agent Answer 0.2 schema closes every object and requires every declared field;
optional claim values are represented explicitly as an empty value or null.
The provider constructor rejects a relaxed schema before any paid request.
Every claim must repeat the evidence packet’s exact epistemic lane, mapping
status, freshness status and authority class. Attempted strengthening fails
reconciliation.
No paid run is part of E4.7 yet. The model lock explicitly records that the
official catalog did not expose a verified dated snapshot identifier in this
environment.
Failure behavior
- Unknown MCP fields and tools fail closed.
- Oversized or deeply nested JSON fails before execution.
- A caller-supplied URL is rejected.
- Unsupported evidence identifiers cause claims to be withheld.
- Source-stated, provisional, unresolved, withheld and conflicting qualifications cannot be silently exchanged.
- Lane, mapping status, freshness status and authority class cannot be silently strengthened or exchanged.
- The spend ceiling is checked conservatively before each provider call.
- One failed reconciliation permits one bounded repair; a second failure ends the run.
Security and conformance
The MCP service is stateless and opens an admitted immutable snapshot with fixtures excluded. The provider process has model credentials but no deployment or origin-acquisition authority. The MCP process has snapshot read access but no model credentials. Conformance requires the embedded nine-tool catalog, bounded parser tests, evidence-escalation tests and local snapshot execution.Implementation status
Local MCP discovery and a two-origin query have passed. The public remote MCP endpoint and frontier-provider run have not been deployed or executed. No benchmark advantage is claimed. The public explanatory paths are/agent/ and /bench/ on twirx.org after
the corresponding website release is admitted.