Charter §5: errors are corrected in place with a visible correction note and a changelog entry. Silent edits are prohibited. This page is that record.
A reader must be able to learn from this site that a verdict was withdrawn. Every entry below names what we published, what was wrong with it, and what we did about it. Entries are append-only; we do not edit or remove them.
Reclassification · ordered by ruling-fe1e80f6906f
What we published. Withdrawn in Necropsy #2 (published build 20260812-021901 onwards): the 40 targets now carry auth-required (unscored) only, with no life-state.
What was wrong. A server that refuses to start without credentials has not been measured, yet 40 targets in the published set carried both a life-state and an auth-required classification. The Charter forbids the combination: auth-required and a life-state are mutually exclusive, and publishing both asserted a measurement the harness never made.
What we did. The 40 targets are reclassified to auth-required only, with install/startup observations where available. This is a correction to our bookkeeping, not a change in anyone's software: the servers did not change, our classification did. It is not counted as a transition in the resurrections/relapses section of Necropsy #2 for that reason.
Affected. 40 targets previously dual-classified (life-state + auth-required)
Reclassification · ordered by ruling-a8674c37e3cd, ruling-ba8642ecbf2c
What we published. Reclassified on the published surface with build 20260811-020357: verdicts withdrawn, targets now published unscored (insufficient-coverage) with the failure mode stated on each page.
What was wrong. The 2026-08-10T02:xx reprobe wave was launched by reprobe-ailing.sh, which hardcodes --kind npm. Thirteen targets in that wave are pypi packages (per the fleet queue), so they were probed against the npm registry, returned E404 in ~2.1 seconds and were stamped sub-floor. Separately, four targets (@azure/mcp, @smartbear/mcp, datadog-mcp-server, @winor30/mcp-server-datadog) were stamped valid=False 'unmeasured: no response within 10s' at 21-73s — above the 8s floor — yet published a life-state. A probe that fails because we asked the wrong registry is indistinguishable, in duration alone, from a package that fails to install; and an aborted probe is a failure path that must terminate in unmeasured, never in a verdict.
What we did. The harness now refuses to publish any life-state derived from a run it stamped invalid (sub-floor-failed OR unmeasured at any duration) — one untrustworthy run is enough, structurally, rather than requiring reproduction. Gate d refuses aborted probes at any duration. The affected targets are published as insufficient-coverage (unscored) with the observed failure mode disclosed: a2a-dm-mcp, ableton-auto-mix-mcp, able-mcp-notable-96, aapt-mcp-server, a2a-mcp-connector, a2a-governance-bridge-mcp, 1wlf-tms-mcp, a11y-expert-mcp, 021-mcp, aa-mcp, a2a-protocol-mcp-server, 5g-ddos-mcp, able-mcp-suitable, @azure/mcp, @smartbear/mcp, datadog-mcp-server, @winor30/mcp-server-datadog. The five named in ruling-a8674c37e3cd were re-probed with the correct registry kind and none reproduced the sub-floor (27-180s valid); the 8 named in ruling-0a6172cae6fd were re-probed earlier the same day with the same result. The remaining fast-but-handshake-OK exemption (@mantine/mcp-server) is a genuinely fast server whose probe demonstrably ran (install + handshake OK in 4.4s) and is not this defect.
Affected. a2a-dm-mcp, ableton-auto-mix-mcp, able-mcp-notable-96, aapt-mcp-server, a2a-mcp-connector, a2a-governance-bridge-mcp, 1wlf-tms-mcp, a11y-expert-mcp, 021-mcp, aa-mcp, a2a-protocol-mcp-server, 5g-ddos-mcp, able-mcp-suitable, @azure/mcp, @smartbear/mcp, datadog-mcp-server, @winor30/mcp-server-datadog
Correction in place · ordered by ruling-cb749b792afc
What we published. From 2026-08-07 21:44 UTC the homepage badged auth-required targets with the life-state 'ailing' and published a status table reading Alive 0 / Ailing 20 / Dead 4, while /api/scores.json and /directory/ on the same build correctly showed those targets as auth-required with no life-state, and yielded 5 ailing. Among the mislabelled targets was @sentry/mcp-server, which had already had a false death withdrawn the day before.
What was wrong. The homepage template derived its badges and its counts from a second, independent walk of the run records that knew nothing of the auth-required and insufficient-coverage classifications the directory and the API applied. Its badge logic fell through to 'ailing' for anything that was not explicitly alive or dead, and its count of ailing servers summed the auth-required targets into it. This was not staleness: it was an internal contradiction inside a single build.
What we did. The homepage now renders from the same classified records /api/scores.json is written from, through one shared badge macro that renders a class rather than inventing a verdict when no life-state exists. Every figure published on any page is now derived from the API feed for that same build, and a verify gate re-derives each one and fails the deploy on any disagreement. Auth-required and insufficient-coverage targets are counted and displayed as unscored, never as a life-state.
Affected. @transcend-io/mcp-server-consent, @sentry/mcp-server, @hubspot/mcp-server, @transcend-io/mcp-server-admin, @transcend-io/mcp-server-inventory, @esaio/esa-mcp-server, @runpod/mcp-server, @transcend-io/mcp-server-assessment and further auth-required targets shown on the homepage between 2026-08-07 and 2026-08-09.
Correction in place · ordered by ruling-cb749b792afc
What we published. /charter/ published a canonical-source link to an RFC 1918 address on the operator's private network, and the charter text named the internal build host.
What was wrong. Neither is useful to a reader — the address is unreachable from the public internet — and both disclose the shape of private infrastructure for no editorial benefit.
What we did. The private address and the internal hostname are stripped from the charter text at render time, so the scrub applies automatically to future amendments rather than depending on someone remembering. The canonical-source link is omitted; there is no public mirror to point at.
Reclassification · ordered by ruling-ab9d0e3fa1f6
What we published. Not published. Recorded here because the classification changed between measurement and publication, and the Charter's correction discipline covers what we nearly got wrong as well as what we did.
What was wrong. @storybook/mcp, a2amcp-sdk, 3tears-mcp and a2anet-mcp each completed a probe faster than the floor at which a run is trustworthy, having failed. A fast failure and a harness that never ran look identical from the outside, and the same signature was the false-death cause described above.
What we did. Each was re-probed with verbose logging roughly 21 hours later and reproduced its failure cause byte-identically, which makes it a property of the target rather than of the harness. They are published as insufficient coverage (unscored), with the observed duration and the specific failure mode stated on each page, and carry no life-state. Two failed because no distribution matching the probe cage's Python exists; two install but expose no runnable entry point. Those are different findings and are labelled separately.
Affected. @storybook/mcp, a2amcp-sdk, 3tears-mcp, a2anet-mcp
Removal of a published page · ordered by ruling-cb749b792afc
What we published. /necropsy/necropsy-2026-08-07/ served publicly for roughly 27 hours after it had been rejected for publication and ordered down.
What was wrong. The page carried more than 130 aggregate numeric scores after numerics were suppressed, cited run IDs from the pre-fix harness window, named five servers dead from precisely the false-death class described in the entry above, published internal test fixtures as though they were ecosystem findings, and made an unsupported claim about 162 servers. It reached the public surface as a stale artifact left in the web root by an earlier deploy, and outlived the release it belonged to because deploys replaced the release directory without sweeping the root.
What we did. The page was removed from the public surface and its removal independently verified off-host with cache busting. A copy is preserved internally with its sha256 as the evidence base for this entry. Deploys now sweep the web root, not only the release directory, so a stale artifact cannot outlive its release again.
Deviation from the order as written. The removal was ordered to return HTTP 410 Gone rather than 404 Not Found. It returns 404. Restoring the retired privileged account needed to edit the server config was judged a worse trade than the semantic difference between the two codes, and the Strategist accepted 404 with this deviation recorded here (ruling-576487b592ce D2). The harm addressed — the serving of rejected content — is fully removed either way.
Withdrawal of a verdict · ordered by ruling-acdb987bfa23
What we published. Between 2026-08-07 02:00 and 2026-08-07 19:06 UTC the directory, the Morgue and the API published life-state verdicts derived from a probe harness that was silently failing to execute anything. Three targets were published as dead on that basis, among them @sentry/mcp-server.
What was wrong. The probe containers mounted their working directory noexec, so installs and handshakes could not run at all. Every probe completed in roughly four seconds having executed nothing, and the scoring engine recorded the resulting universal failure as a property of the software rather than of the instrument. A harness that cannot run a server cannot distinguish a dead server from a server it never started.
What we did. Every score from the pre-fix window was purged from the publishable set; only runs at or after run-reprobe-20260807-190629 may be published. The three dead verdicts are withdrawn in full. Two of the three targets are auth-required and therefore carry no life-state at all; the third returns alive on a valid probe. Aggregate numeric scores were suppressed fleet-wide at the same time, because an audit found the v1.0 rubric axes returned constants across the alive cohort and the numbers overstated a precision they did not have.
Affected. @sentry/mcp-server and two further targets published dead 2026-08-07; all numeric scores published before 2026-08-07.
Amendments to the Operating Charter require a Strategist session and an entry here. This table is read directly from Appendix A of the governing document, so it cannot drift from it.
| Version | Date | Author | Change |
|---|---|---|---|
| No changelog rows found in the Charter. | |||
The Charter has not been amended since its initial version. Corrections to published data, listed above, are a separate record and are far more frequent — that asymmetry is intentional.