Part 12 of 16
MCP surface
All 118 tools with their full input schemas, the local-versus-hosted boundary tested honestly, and a standing disclosure of where our own docs and code disagree.
- The MCP surfaceThe daemon's MCP listener: the four JSON-RPC methods that exist, the 118-tool catalogue, how grants filter tools/list, and why omitting token_budget on query returns unbounded results.
- Tool reference, part 1Complete reference for 70 of the 118 MCP tools - handshake, retrieval, facts, memory, sessions, audit posture, passports and sync - every parameter, default, output, flag and token_budget rule.
- Tool reference, part 2Complete reference for the remaining 49 MCP tools - coordination, GitHub, substrate, features, traces, approvals, orchestrators, punchcards - including the ten advertised tools that return 501.
- Local versus hostedWhich MCP tools are hosted-gated, what "absent from the local token catalogue" does and does not mean, and the three caveats - including that enforcement fails open without an RCX router.
- Flag parsing and known driftA standing disclosure: six incompatible environment-flag dialects, a tool that misdescribes its own flag default, eight places our docs contradict our code, and why CI cannot catch any of it.

