MCP SDK Tier Audit: modelcontextprotocol/php-sdk
SDK: modelcontextprotocol/php-sdk
Version: v0.7.1 (published 2026-08-14, pre-1.0) · assessed on main @ 8c06dce
Date: 2026-08-19
Requirements revisions scored: 2025-11-25 and 2026-07-28 (frozen per-revision requirement sets, each run at that revision's own wire version, per @modelcontextprotocol/conformance 0.2.0-alpha.11)
Auditor: mcp-sdk-tier-audit skill (tier-check CLI + subagent evaluation)
Previous assessment: Tier 3 (#2305, 2026-02-23, v0.4.0)
Result
Tier 3. Server-side conformance is excellent (100%, 67/67) and every process signal (triage, labels, P0 handling, spec tracking, dependency policy, roadmap) passes. Two hard requirements block Tier 2: client conformance is only 20% (10/50), almost entirely because OAuth/authorization client scenarios are unimplemented or failing (38 of 39 scored auth scenarios), and no stable 1.0.0+ release has ever shipped (current: v0.7.1). Documentation gaps (38/48 features) and a missing versioning policy further block Tier 1.
All 40 client failures are pre-declared as expected in the SDK's own baseline files (conformance-baseline-2025-11-25.yml, conformance-baseline-2026-07-28.yml) — this is a tracked, deliberate OAuth gap (matching the in-progress auth work called out in ROADMAP.md), not silent breakage. Per SEP-1730 the score is still the raw pass rate regardless of baseline, so this doesn't change the tier — but it's worth knowing the gap is fully tracked, not accidental.
| # |
Requirement |
Tier 1 Standard |
Tier 2 Standard |
Value |
T1 |
T2 |
| 1a |
Server Conformance |
100% pass rate |
≥ 80% pass rate |
100% (67/67 across both revisions) |
✅ |
✅ |
| 1b |
Client Conformance |
100% pass rate |
≥ 80% pass rate |
20% (10/50 across both revisions) |
❌ |
❌ |
| 2 |
Issue Triage |
≥ 90% within 2 biz days |
≥ 80% within 1 month |
100% (69/69) |
✅ |
✅ |
| 2b |
Labels |
12 required labels |
12 required labels |
12/12 |
✅ |
✅ |
| 3 |
Critical Bug Resolution |
All P0s within 7 days |
All P0s within 2 weeks |
0 open |
✅ |
✅ |
| 4 |
Stable Release |
Required + clear versioning |
At least one stable release |
v0.7.1 (pre-1.0) |
❌ |
❌ |
| 4b |
Spec Tracking |
Timeline agreed per release |
Within 6 months |
17d gap |
✅ |
✅ |
| 5 |
Documentation |
Comprehensive w/ examples |
Basic docs for core features |
38/48 features (core 31/36, 86%) |
❌ |
✅ |
| 6 |
Dependency Policy |
Published update policy |
Published update policy |
dependabot.yml configured |
✅ |
✅ |
| 7 |
Roadmap |
Published roadmap |
Plan toward Tier 1 |
ROADMAP.md, substantive |
✅ |
✅ |
| 8 |
Versioning Policy |
Documented breaking change policy |
N/A |
Not found |
❌ |
N/A |
Tier 1: 6/8 met (failing: Client Conformance, Stable Release, Documentation, Versioning Policy)
Tier 2: 5/7 met (failing: Client Conformance, Stable Release)
1–2. Conformance — ✅ server 67/67, ❌ client 10/50
Scored against the frozen 2025-11-25 and 2026-07-28 requirement sets, each run at its own wire, against the SDK's own everything-server/client conformance fixtures. The repo carries baseline files at tests/Conformance/conformance-baseline-{2025-11-25,2026-07-28}.yml — every client failure below matches an entry in one of them.
Server — 67/67 (100%)
30/30 scored at 2025-11-25, 37/37 scored at 2026-07-28. Not scored (informational): server-sse-polling/server-session-lifecycle/json-schema-2020-12 (pending/added-after-release, all passing anyway), 10 tasks-* scenarios at 2026-07-28 (extension, SEP-2663 not yet implemented, all failing) plus http-header-validation/http-custom-header-server-validation (pending).
All 67 scored server scenarios (100% pass)
| Scenario |
Scored at |
Status |
| tools-list |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-with-progress |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-with-logging |
2025-11-25 |
PASS |
| tools-call-simple-text |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-sampling |
2025-11-25 |
PASS |
| tools-call-mixed-content |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-image |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-error |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-embedded-resource |
2025-11-25, 2026-07-28 |
PASS |
| tools-call-elicitation |
2025-11-25 |
PASS |
| tools-call-audio |
2025-11-25, 2026-07-28 |
PASS |
| server-sse-multiple-streams |
2025-11-25, 2026-07-28 |
PASS |
| server-initialize |
2025-11-25 |
PASS |
| server-stateless |
2026-07-28 |
PASS |
| resources-unsubscribe |
2025-11-25 |
PASS |
| resources-templates-read |
2025-11-25, 2026-07-28 |
PASS |
| resources-subscribe |
2025-11-25 |
PASS |
| resources-read-text |
2025-11-25, 2026-07-28 |
PASS |
| resources-read-binary |
2025-11-25, 2026-07-28 |
PASS |
| resources-list |
2025-11-25, 2026-07-28 |
PASS |
| prompts-list |
2025-11-25, 2026-07-28 |
PASS |
| prompts-get-with-image |
2025-11-25, 2026-07-28 |
PASS |
| prompts-get-with-args |
2025-11-25, 2026-07-28 |
PASS |
| prompts-get-simple |
2025-11-25, 2026-07-28 |
PASS |
| prompts-get-embedded-resource |
2025-11-25, 2026-07-28 |
PASS |
| ping |
2025-11-25 |
PASS |
| logging-set-level |
2025-11-25 |
PASS |
| elicitation-sep1330-enums |
2025-11-25 |
PASS |
| elicitation-sep1034-defaults |
2025-11-25 |
PASS |
| dns-rebinding-protection |
2025-11-25, 2026-07-28 |
PASS |
| completion-complete |
2025-11-25, 2026-07-28 |
PASS |
| sep-2164-resource-not-found |
2026-07-28 |
PASS |
| input-required-result-validate-input |
2026-07-28 |
PASS |
| input-required-result-unsupported-methods |
2026-07-28 |
PASS |
| input-required-result-tampered-state |
2026-07-28 |
PASS |
| input-required-result-result-type |
2026-07-28 |
PASS |
| input-required-result-request-state |
2026-07-28 |
PASS |
| input-required-result-non-tool-request |
2026-07-28 |
PASS |
| input-required-result-multiple-input-requests |
2026-07-28 |
PASS |
| input-required-result-multi-round |
2026-07-28 |
PASS |
| input-required-result-missing-input-response |
2026-07-28 |
PASS |
| input-required-result-ignore-extra-params |
2026-07-28 |
PASS |
| input-required-result-capability-check |
2026-07-28 |
PASS |
| input-required-result-basic-sampling |
2026-07-28 |
PASS |
| input-required-result-basic-list-roots |
2026-07-28 |
PASS |
| input-required-result-basic-elicitation |
2026-07-28 |
PASS |
| caching |
2026-07-28 |
PASS |
Not scored (extension, all failing — SEP-2663 Tasks not yet implemented): tasks-wire-fields, tasks-status-notifications, tasks-required-task-error, tasks-request-state-removal, tasks-request-headers, tasks-mrtr-input, tasks-mrtr-composition, tasks-lifecycle, tasks-dispatch-and-envelope, tasks-capability-negotiation (all @ 2026-07-28).
Client — 10/50 (20%)
Suite breakdown: Core 9/11 (82%), Auth 1/39 (2.6%). Failures split as 2 core failures (sse-retry, elicitation-sep1034-client-defaults, both @ 2025-11-25) + 38 auth failures (14/14 of 2025-11-25's scored auth scenarios; 24/25 of 2026-07-28's, everything except auth/resource-mismatch). All 40 failures — every one, both revisions — match an entry in the SDK's own baseline files. This is a known, tracked OAuth gap, not silent breakage or drift; SEP-1730 still scores the raw pass rate regardless, so it remains a hard blocker for both Tier 1 and Tier 2 since auth scenarios are 39 of the 50 scored (78%) and virtually all fail.
Core scenarios — 9/11 (82%)
| Scenario |
Scored at |
Status |
Baselined? |
| tools_call |
2025-11-25, 2026-07-28 |
PASS |
— |
| initialize |
2025-11-25 |
PASS |
— |
| sse-retry |
2025-11-25 |
FAIL |
Yes |
| elicitation-sep1034-client-defaults |
2025-11-25 |
FAIL |
Yes |
| sep-2322-client-request-state |
2026-07-28 |
PASS |
— |
| request-metadata |
2026-07-28 |
PASS |
— |
| json-schema-ref-no-deref |
2026-07-28 |
PASS |
— |
| http-standard-headers |
2026-07-28 |
PASS |
— |
| http-invalid-tool-headers |
2026-07-28 |
PASS |
— |
| http-custom-headers |
2026-07-28 |
PASS |
— |
Auth scenarios — 1/39 (2.6%) — the primary Tier 2/1 blocker (all failures baselined)
| Scenario |
Scored at |
Status |
Baselined? |
| auth/resource-mismatch |
2026-07-28 |
PASS |
— |
| auth/token-endpoint-auth-post |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/token-endpoint-auth-none |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/token-endpoint-auth-basic |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/scope-step-up |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/scope-retry-limit |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/scope-omitted-when-undefined |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/scope-from-www-authenticate |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/scope-from-scopes-supported |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/pre-registration |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/metadata-var3 |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/metadata-var2 |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/metadata-var1 |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/metadata-default |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/basic-cimd |
2025-11-25, 2026-07-28 |
FAIL |
Yes |
| auth/offline-access-scope |
2026-07-28 |
FAIL |
Yes |
| auth/offline-access-not-supported |
2026-07-28 |
FAIL |
Yes |
| auth/metadata-issuer-mismatch |
2026-07-28 |
FAIL |
Yes |
| auth/iss-wrong-issuer |
2026-07-28 |
FAIL |
Yes |
| auth/iss-unexpected |
2026-07-28 |
FAIL |
Yes |
| auth/iss-supported-missing |
2026-07-28 |
FAIL |
Yes |
| auth/iss-supported |
2026-07-28 |
FAIL |
Yes |
| auth/iss-not-advertised |
2026-07-28 |
FAIL |
Yes |
| auth/iss-normalized |
2026-07-28 |
FAIL |
Yes |
| auth/authorization-server-migration |
2026-07-28 |
FAIL |
Yes (partial-check entry) |
Not scored (extension, both revisions): auth/wif-jwt-bearer (FAIL), auth/enterprise-managed-authorization (FAIL), auth/dpop-nonce (FAIL), auth/dpop (FAIL), auth/client-credentials-jwt (PASS), auth/client-credentials-basic (PASS).
3–4. Issue Triage and P0 Resolution — ✅
100% compliance (69/69 issues triaged within SLA), all 12 required labels present, 0 open P0s and no P0 history to audit for mislabeling or slow resolution.
5–6. Stable Release and Spec Tracking
Stable Release — ❌. Latest release is v0.7.1 (published 2026-08-14), pre-1.0. No release ≥ 1.0.0 has ever shipped. This alone blocks both Tier 1 and Tier 2 ("at least one stable release ≥ 1.0.0").
Spec Tracking — ✅. v0.7.1 shipped 17 days after the 2026-07-28 spec revision, well within the 6-month Tier 2 window and the Tier 1 timeline-agreed standard.
7. Documentation — ❌ 38/48 (79%), core 31/36 (86%)
Documentation lives in docs/ (mcp-elements.md, client.md, server-builder.md, transports.md, server-client-communication.md, events.md, extensions.md, examples.md), each generally paired with runnable examples in examples/. 10 of 48 canonical features are undocumented or under-documented — 8 outright FAIL, 2 PARTIAL:
| # |
Feature |
Status |
Note |
| 14 |
Resources - subscribing |
FAIL |
Implemented (ResourceSubscribeHandler.php), zero prose docs |
| 15 |
Resources - unsubscribing |
FAIL |
Implemented (ResourceUnsubscribeRequest.php), zero prose docs |
| 20 |
Prompts - embedded resources |
PARTIAL |
Generic prose exists, no dedicated example |
| 25 |
Elicitation - URL mode |
FAIL |
Implemented (ElicitRequest.php, ElicitationMode::Url), zero prose docs |
| 27 |
Elicitation - default values |
PARTIAL |
Example exists (ElicitationHandlers.php), no prose explanation |
| 29 |
Elicitation - complete notification |
FAIL |
Not implemented — no notifications/elicitation/complete handling |
| 36 |
Ping |
FAIL |
Implemented (PingHandler.php), zero prose docs |
| 39 |
SSE transport - legacy (client) |
FAIL |
Not implemented |
| 40 |
SSE transport - legacy (server) |
FAIL |
Not implemented |
| 44 |
Cancellation |
FAIL |
Implemented (CancelledNotification.php), zero prose docs |
The remaining 38/48 features (79%) are documented with prose + at least one example. Core-feature coverage (86%, 31/36) already satisfies the Tier 2 basic-docs bar.
8. Versioning Policy — ❌
No VERSIONING.md, docs/versioning.md, BREAKING_CHANGES.md, or CONTRIBUTING.md versioning section exists. CHANGELOG.md does tag individual entries with [BC Break] markers, which shows breaking changes are tracked in practice, but there is no standalone policy document describing what constitutes a breaking change, how it's communicated ahead of a release, or the SemVer commitment.
Dependency Policy and Roadmap — ✅
- Dependency policy: .github/dependabot.yml — real weekly update schedules for composer and github-actions, not a stub.
- Roadmap: ROADMAP.md — concrete, checkbox-tracked items tied to spec components (OAuth2 auth for server/client, schema generation, "achieve full spec conformance," Tasks extension), some already checked off. Functions as both a Tier 1 roadmap and a Tier 2 plan-toward-Tier-1.
Path to Tier 2
- Raise client conformance from 20% to ≥ 80% (Large) — almost entirely OAuth client work: metadata discovery variants, token endpoint auth methods (post/none/basic), scope handling (step-up, retry-limit, omitted, from-www-authenticate, from-scopes-supported), dynamic client registration, issuer validation, offline-access scopes, authorization-server-migration. All of this is already tracked in the repo's own baseline files and ROADMAP.md — the work is scoped, it just isn't done yet.
- Fix sse-retry and elicitation-sep1034-client-defaults (Medium) — the two non-auth client failures, both @ 2025-11-25.
- Ship a stable 1.0.0+ release (Medium).
Path to Tier 1
Everything above, plus:
- Raise client conformance to 100% (full OAuth coverage, not just the 80% bar).
- Document the 10 gaps listed above (mostly small per-feature doc additions; legacy SSE transport and elicitation-complete-notification need either an implementation or an explicit "intentionally not implemented" note, since undocumented-because-unimplemented reads the same as a real gap).
- Publish a versioning/breaking-change policy (new VERSIONING.md, or a "Versioning" section in a new CONTRIBUTING.md — the existing CHANGELOG.md [BC Break] convention could be formalized into it).
Recommendation: OAuth client conformance is the single highest-leverage fix — it alone blocks both tiers and accounts for 38 of 40 client failures. It's already declared as a known gap (baseline files + ROADMAP.md OAuth2 line items) and matches the in-progress auth PRs mentioned in the prior Tier 3 assessment (#2305); closing it is what actually moves the tier, since SEP-1730 doesn't credit baselined failures toward the score. Everything else needed for Tier 2 (server conformance, triage, labels, P0 handling, spec tracking, dependency policy, roadmap) already passes.
Reproduce This Assessment
git clone https://github.com/modelcontextprotocol/conformance.git && cd conformance
git checkout 74edef3 && npm install && npm run build # 0.2.0-alpha.11 + #458
git clone https://github.com/modelcontextprotocol/php-sdk.git ../mcp-sdk
cd ../mcp-sdk && composer install && cd -
php -S 127.0.0.1:8000 ../mcp-sdk/tests/Conformance/server.php & # one endpoint serves both eras
node dist/index.js tier-check \
--repo modelcontextprotocol/php-sdk --branch main \
--conformance-server-url http://localhost:8000/ \
--client-cmd 'php ../mcp-sdk/tests/Conformance/client.php' \
--requirements 2025-11-25,2026-07-28 --output markdown
Note: the SDK's own CI instead drives this via Docker Compose (tests/Conformance/Fixtures/docker-compose.yml) and applies tests/Conformance/conformance-baseline-*.yml as --expected-failures to the upstream @modelcontextprotocol/conformance CLI directly — this audit didn't have the SDK wired into known-sdks.ts, so it ran unadjusted via the URL fallback above and cross-referenced the baseline files manually afterward.
Or via the /mcp-sdk-tier-audit skill in Claude Code:
/mcp-sdk-tier-audit ../mcp-sdk http://localhost:8000/ "php ../mcp-sdk/tests/Conformance/client.php" --requirements 2025-11-25,2026-07-28
Automated assessment (tier-check CLI + AI subagent evaluation for documentation/policy content) — flag anything that looks wrong.
@pcarleton @felixweinberger
MCP SDK Tier Audit: modelcontextprotocol/php-sdk
SDK: modelcontextprotocol/php-sdk
Version: v0.7.1 (published 2026-08-14, pre-1.0) · assessed on main @ 8c06dce
Date: 2026-08-19
Requirements revisions scored: 2025-11-25 and 2026-07-28 (frozen per-revision requirement sets, each run at that revision's own wire version, per @modelcontextprotocol/conformance 0.2.0-alpha.11)
Auditor: mcp-sdk-tier-audit skill (tier-check CLI + subagent evaluation)
Previous assessment: Tier 3 (#2305, 2026-02-23, v0.4.0)
Result
Tier 3. Server-side conformance is excellent (100%, 67/67) and every process signal (triage, labels, P0 handling, spec tracking, dependency policy, roadmap) passes. Two hard requirements block Tier 2: client conformance is only 20% (10/50), almost entirely because OAuth/authorization client scenarios are unimplemented or failing (38 of 39 scored auth scenarios), and no stable 1.0.0+ release has ever shipped (current: v0.7.1). Documentation gaps (38/48 features) and a missing versioning policy further block Tier 1.
All 40 client failures are pre-declared as expected in the SDK's own baseline files (conformance-baseline-2025-11-25.yml, conformance-baseline-2026-07-28.yml) — this is a tracked, deliberate OAuth gap (matching the in-progress auth work called out in ROADMAP.md), not silent breakage. Per SEP-1730 the score is still the raw pass rate regardless of baseline, so this doesn't change the tier — but it's worth knowing the gap is fully tracked, not accidental.
Tier 1: 6/8 met (failing: Client Conformance, Stable Release, Documentation, Versioning Policy)
Tier 2: 5/7 met (failing: Client Conformance, Stable Release)
1–2. Conformance — ✅ server 67/67, ❌ client 10/50
Scored against the frozen 2025-11-25 and 2026-07-28 requirement sets, each run at its own wire, against the SDK's own everything-server/client conformance fixtures. The repo carries baseline files at tests/Conformance/conformance-baseline-{2025-11-25,2026-07-28}.yml — every client failure below matches an entry in one of them.
Server — 67/67 (100%)
30/30 scored at 2025-11-25, 37/37 scored at 2026-07-28. Not scored (informational): server-sse-polling/server-session-lifecycle/json-schema-2020-12 (pending/added-after-release, all passing anyway), 10 tasks-* scenarios at 2026-07-28 (extension, SEP-2663 not yet implemented, all failing) plus http-header-validation/http-custom-header-server-validation (pending).
All 67 scored server scenarios (100% pass)Not scored (extension, all failing — SEP-2663 Tasks not yet implemented): tasks-wire-fields, tasks-status-notifications, tasks-required-task-error, tasks-request-state-removal, tasks-request-headers, tasks-mrtr-input, tasks-mrtr-composition, tasks-lifecycle, tasks-dispatch-and-envelope, tasks-capability-negotiation (all @ 2026-07-28).
Client — 10/50 (20%)
Suite breakdown: Core 9/11 (82%), Auth 1/39 (2.6%). Failures split as 2 core failures (sse-retry, elicitation-sep1034-client-defaults, both @ 2025-11-25) + 38 auth failures (14/14 of 2025-11-25's scored auth scenarios; 24/25 of 2026-07-28's, everything except auth/resource-mismatch). All 40 failures — every one, both revisions — match an entry in the SDK's own baseline files. This is a known, tracked OAuth gap, not silent breakage or drift; SEP-1730 still scores the raw pass rate regardless, so it remains a hard blocker for both Tier 1 and Tier 2 since auth scenarios are 39 of the 50 scored (78%) and virtually all fail.
Core scenarios — 9/11 (82%)Not scored (extension, both revisions): auth/wif-jwt-bearer (FAIL), auth/enterprise-managed-authorization (FAIL), auth/dpop-nonce (FAIL), auth/dpop (FAIL), auth/client-credentials-jwt (PASS), auth/client-credentials-basic (PASS).
3–4. Issue Triage and P0 Resolution — ✅
100% compliance (69/69 issues triaged within SLA), all 12 required labels present, 0 open P0s and no P0 history to audit for mislabeling or slow resolution.
5–6. Stable Release and Spec Tracking
Stable Release — ❌. Latest release is v0.7.1 (published 2026-08-14), pre-1.0. No release ≥ 1.0.0 has ever shipped. This alone blocks both Tier 1 and Tier 2 ("at least one stable release ≥ 1.0.0").
Spec Tracking — ✅. v0.7.1 shipped 17 days after the 2026-07-28 spec revision, well within the 6-month Tier 2 window and the Tier 1 timeline-agreed standard.
7. Documentation — ❌ 38/48 (79%), core 31/36 (86%)
Documentation lives in docs/ (mcp-elements.md, client.md, server-builder.md, transports.md, server-client-communication.md, events.md, extensions.md, examples.md), each generally paired with runnable examples in examples/. 10 of 48 canonical features are undocumented or under-documented — 8 outright FAIL, 2 PARTIAL:
The remaining 38/48 features (79%) are documented with prose + at least one example. Core-feature coverage (86%, 31/36) already satisfies the Tier 2 basic-docs bar.
8. Versioning Policy — ❌
No VERSIONING.md, docs/versioning.md, BREAKING_CHANGES.md, or CONTRIBUTING.md versioning section exists. CHANGELOG.md does tag individual entries with [BC Break] markers, which shows breaking changes are tracked in practice, but there is no standalone policy document describing what constitutes a breaking change, how it's communicated ahead of a release, or the SemVer commitment.
Dependency Policy and Roadmap — ✅
Path to Tier 2
Path to Tier 1
Everything above, plus:
Recommendation: OAuth client conformance is the single highest-leverage fix — it alone blocks both tiers and accounts for 38 of 40 client failures. It's already declared as a known gap (baseline files + ROADMAP.md OAuth2 line items) and matches the in-progress auth PRs mentioned in the prior Tier 3 assessment (#2305); closing it is what actually moves the tier, since SEP-1730 doesn't credit baselined failures toward the score. Everything else needed for Tier 2 (server conformance, triage, labels, P0 handling, spec tracking, dependency policy, roadmap) already passes.
Reproduce This Assessment
Note: the SDK's own CI instead drives this via Docker Compose (tests/Conformance/Fixtures/docker-compose.yml) and applies tests/Conformance/conformance-baseline-*.yml as --expected-failures to the upstream @modelcontextprotocol/conformance CLI directly — this audit didn't have the SDK wired into known-sdks.ts, so it ran unadjusted via the URL fallback above and cross-referenced the baseline files manually afterward.
Or via the /mcp-sdk-tier-audit skill in Claude Code:
Automated assessment (tier-check CLI + AI subagent evaluation for documentation/policy content) — flag anything that looks wrong.
@pcarleton @felixweinberger