WagerX Tech · Signed execution evidence

Autonomous run
receipt.

This signed, tamper-evident record shows what WagerX discovered, rejected, selected and called—or how another agentic service discovered WagerX—under its bounded research policy.

SUCCESS
arun-c466c1bfd76e4b5bbe065440
Research authoritative Microsoft security guidance for securing remote Model Context Protocol servers and return the most relevant source evidence.

Microsoft Learn returned guidance that remote MCP deployments should receive a security review across the server, client, agent and model-provider boundary, with Entra ID authentication, secure token management and network isolation among the recommended controls.

Created
Completed
Policy
autonomous-read-only-v1 · max 2 candidates · 1 tool call
Route
Agenstry A2A discovery → Microsoft Learn MCP Server → microsoft_docs_search
SHA-256
87a16ca6e807940185b9198d5c37bd91ca7a6d7909caff4c526ff1899c932876
Signature
YX9XirrfbTX0H_uYtZMU37fBO9Qj7rvK_YTa5G_GXGkV04-BCwXViCrA-Jl5hIrLOPldiXjiLbnH1Gqat9ZKDQ

Machine-readable evidence

  1. Signed JSON receipt
  2. Ed25519 public key
Execution stages
  1. Policy — accepted · WagerX
    Public HTTPS; no auth, payments, writes, redirects or supplied URLs; at most two candidates and one tool call.
  2. A2a Discovery — success · Agenstry · message/send · find_mcp · 740 ms
    Discovered and retained 2 bounded candidates.
  3. Candidate Validation — selected · Microsoft Learn MCP · microsoft_docs_search · 824 ms
    Live handshake passed; no auth challenge; tool name, description and input schema passed independent read-only screening.
  4. Mcp Execution — success · Microsoft Learn MCP · microsoft_docs_search · 1629 ms
    Exactly one read-only tools/call completed.

Remote result links

  1. https://learn.microsoft.com/api/mcp
  2. https://learn.microsoft.com/en-us/azure/api-management/secure-mcp-servers
  3. https://modelcontextprotocol.io/specification/draft/basic/security_best_practices
  4. https://techcommunity.microsoft.com/blog/microsoft-security-blog/understanding-and-mitigating-security-risks-in-mcp-implementations/4404667
Integrity and trust boundary

The signature proves WagerX finalized this exact receipt. It does not independently prove that a remote provider statement is true.

When an archived receipt is restored from deployment seed data, the active deployment re-signs the recorded facts. That signature does not independently prove the original capture time.

Remote text was displayed as data only. It could not choose another route, tool or action.