Skip to main content
New

2 minute read

Trooth command-line tool 0.12.0: MCP tool fingerprints, more of the public record, and a hardware key for the log

Trooth now fingerprints the tools Model Context Protocol (MCP) servers list and enters every change in its log, the public record adds federal contracting, patents, state registers, merger review and the domain's registration, and every checkpoint of the log is also signed by a key held in hardware.

What changed

Once a day Trooth reads the tool list of each MCP server it follows, with no credentials, fingerprints each tool's description and its whole definition, and signs and logs a statement naming the list whenever it changes, so the log holds each server's history of tool changes. trooth mcp-tools checks those fingerprints, the statement and its log entry, and with --live compares them with what the server lists now. The public record reading adds federal contractor registrations and exclusions from SAM.gov, patent applications from the USPTO, entries with the exact legal name in the New York, Colorado, Connecticut and Oregon business registers, FTC early termination notices under the Hart-Scott-Rodino Act, the domain's registration, the changes those sources record, and every subject the reading names. Every checkpoint of the log now carries a second signature by a key generated inside AWS Key Management Service, which never leaves its hardware; trooth log checkpoint says whether it is there.

Why it changed

An agent decides what a tool does from the description its server lists, and a server can change that description after it was reviewed without telling anyone. A fingerprint in a public log makes the change visible. A log key held only in software can be copied; a key that never leaves a hardware module cannot.

Who is affected

  • Affected: Anyone connecting an agent to an MCP server, anyone relying on a company's public record, and anyone watching the log.
  • Availability: npm, as trooth 0.12.0; on Trust Profiles, in the Identity section. No account.
  • Release stage: Available.
  • Areas: CLI, API.

What to do

No action required. Nothing is required. Run trooth mcp-tools with a server's address and --live to see whether it still lists the tools Trooth recorded.

Versions and migration

  • trooth: 0.12.0

Dates

  • Announced: October 7, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 7, 2026.

What this does not fix

A fingerprint says what a server listed, not what a tool does. A name match in SAM.gov, a state register or a merger notice is not an identification. SAM.gov is read for a few names a day, and only once Trooth holds its key; the USPTO likewise. The witnesses still follow the software key, and one person administers both keys; Trooth has no second approver, and docs/KEY-CEREMONY.md says what stands in its place.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent