Skip to content

MCP Declared-Manifest / Runtime-Surface Divergence

mcp-manifest-runtime-divergence is a high severity check in the ai category, written in python. Its source is templates/ai/mcp/mcp-manifest-runtime-divergence.py in cert-x-gen-templates.

DIFF check. Fetches the surface an MCP server DECLARED (its MCP Registry server.json / packaged manifest / pinned lockfile copy) and the surface it is actually SERVING (live tools/list + resources/list), and reports every place the running server is wider than its declaration - an undeclared tool, an undeclared input-schema property, a tool scope (annotation) looser at runtime than declared, an undeclared resource, or a server version / package hash that is not the published one. One instant, two sources; no baseline and no waiting.

Field Value
Id mcp-manifest-runtime-divergence
Severity high
Language python
Category ai
Author Bugb Research
Template version 1.0.0
Confidence 92
CVSS 8.2
Weakness CWE-345, CWE-494
Tags mcp, ai, agent, supply-chain, registry, manifest, integrity, divergence, behavioural, http, cwe-345, cwe-494
Target kind http
Oracle diff

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info mcp-manifest-runtime-divergence

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.