Status: Mapped Layer: runtime
§Scope
mcp-server/src/tools/ (41 modules) and mcp-server/contracts/; MCP handlers implementing evidence, findings, files, seams, dispatch, locks, staleness, materialization and queries, plus the living-conspectus surfaces added since onboarding — claims, change impact, revalidation, resolution, refresh, review and review sessions, composition, codebase briefs, design sessions, decisions, research, crosswalk, learning, evaluation, and the Chorusmith adapter.
§Start here
mcp-server/src/tools/evidence.ts; mcp-server/src/tools/git.ts; mcp-server/src/tools/dispositions.ts
§Notes
Large mutation and validation surface coupled to B-02 schema/invariants. Grew from 24 to 41 modules between b8b566f and 5694080; the seventeen added modules have a file ledger but no concern pass (open question 9), so the sixteen b8b566f dispositions cover roughly half the subsystem. Three findings recorded in the 2026-08-27 refresh: B03-1 (ledger never reconciled against the tree), B03-2 (staleness surface inert), B03-3 (evidence-quality vocabulary narrower than the published ladder).
§File ledger
activation-parity.schema.json
- Path
mcp-server/contracts/activation-parity.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
artifact-input.schema.json
- Path
mcp-server/contracts/chorusmith/artifact-input.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
custody-matrix.json
- Path
mcp-server/contracts/chorusmith/custody-matrix.json- Review
- candidate
- Revision
5694080
Why this file is in scope
extraction-parity-ledger.json
- Path
mcp-server/contracts/chorusmith/extraction-parity-ledger.json- Review
- candidate
- Revision
5694080
Why this file is in scope
project-type.json
- Path
mcp-server/contracts/chorusmith/project-type.json- Review
- candidate
- Revision
5694080
Why this file is in scope
run-manifest.schema.json
- Path
mcp-server/contracts/chorusmith/run-manifest.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
codebase-brief.schema.json
- Path
mcp-server/contracts/codebase-brief.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
codebase-decision.schema.json
- Path
mcp-server/contracts/codebase-decision.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
historical-evaluation-corpus.schema.json
- Path
mcp-server/contracts/historical-evaluation-corpus.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
research-request.schema.json
- Path
mcp-server/contracts/research-request.schema.json- Review
- candidate
- Revision
5694080
Why this file is in scope
chorusmith-adapter.ts
- Path
mcp-server/src/tools/chorusmith-adapter.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
claims.ts
- Path
mcp-server/src/tools/claims.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
codebase-brief.ts
- Path
mcp-server/src/tools/codebase-brief.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
composition.ts
- Path
mcp-server/src/tools/composition.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
crosswalk.ts
- Path
mcp-server/src/tools/crosswalk.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
decisions.ts
- Path
mcp-server/src/tools/decisions.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
design-session.ts
- Path
mcp-server/src/tools/design-session.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
evaluation.ts
- Path
mcp-server/src/tools/evaluation.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
impact.ts
- Path
mcp-server/src/tools/impact.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
learning.ts
- Path
mcp-server/src/tools/learning.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
refresh.ts
- Path
mcp-server/src/tools/refresh.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
research.ts
- Path
mcp-server/src/tools/research.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
resolution.ts
- Path
mcp-server/src/tools/resolution.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
revalidation.ts
- Path
mcp-server/src/tools/revalidation.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
review-analysis.ts
- Path
mcp-server/src/tools/review-analysis.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
review-session.ts
- Path
mcp-server/src/tools/review-session.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
review.ts
- Path
mcp-server/src/tools/review.ts- Review
- candidate
- Revision
5694080
Why this file is in scope
artifacts.ts
- Path
mcp-server/src/tools/artifacts.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
compare.ts
- Path
mcp-server/src/tools/compare.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
concerns.ts
- Path
mcp-server/src/tools/concerns.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
contradictions.ts
- Path
mcp-server/src/tools/contradictions.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
dashboard.ts
- Path
mcp-server/src/tools/dashboard.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
diagnosticity.ts
- Path
mcp-server/src/tools/diagnosticity.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
dispatch.ts
- Path
mcp-server/src/tools/dispatch.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
dispositions.ts
- Path
mcp-server/src/tools/dispositions.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
evidence.ts
- Path
mcp-server/src/tools/evidence.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
field-notes.ts
- Path
mcp-server/src/tools/field-notes.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
files.ts
- Path
mcp-server/src/tools/files.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
findings.ts
- Path
mcp-server/src/tools/findings.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
git.ts
- Path
mcp-server/src/tools/git.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
locks.ts
- Path
mcp-server/src/tools/locks.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
logging.ts
- Path
mcp-server/src/tools/logging.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
materialize.ts
- Path
mcp-server/src/tools/materialize.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
open-questions.ts
- Path
mcp-server/src/tools/open-questions.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
project.ts
- Path
mcp-server/src/tools/project.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
seams.ts
- Path
mcp-server/src/tools/seams.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
stale.ts
- Path
mcp-server/src/tools/stale.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
storage-history.ts
- Path
mcp-server/src/tools/storage-history.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
subsystems.ts
- Path
mcp-server/src/tools/subsystems.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
vocabulary.ts
- Path
mcp-server/src/tools/vocabulary.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
xrefs.ts
- Path
mcp-server/src/tools/xrefs.ts- Review
- examined
- Revision
b8b566f
Why this file is in scope
§Concern review
AT-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
AT-2
- Verdict
- Competing explanations
- Evidence
- Code verified
- Linchpin dependency
- 🔗
Rationale
CC-1
- Verdict
- Out of scope
- Evidence
- Code verified
Rationale
CR-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
EP-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
EP-2
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
IF-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
RL-1
- Verdict
- Competing explanations
- Evidence
- Code verified
- Linchpin dependency
- 🔗
Rationale
RL-2
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
SC-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
SC-2
- Verdict
- Out of scope
- Evidence
- Code verified
Rationale
SC-6
- Verdict
- Confirmed defect
- Evidence
- Code verified
Rationale
SD-1
- Verdict
- Confirmed defect
- Evidence
- Code verified
Rationale
SI-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
SI-2
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
TB-1
- Verdict
- Competing explanations
- Evidence
- Code verified
- Linchpin dependency
- 🔗
Rationale
TR-1
- Verdict
- Accepted behavior
- Evidence
- Code verified
Rationale
TR-2
- Verdict
- Out of scope
- Evidence
- Code verified
Rationale
VG-1
- Verdict
- Confirmed defect
- Evidence
- Code verified
Rationale
§Findings
§B03-1 · High · fixed
Symptom: A subsystem can report status 'mapped' with zero stale entries while an arbitrary fraction of its declared scope has never been classified, and while ledger rows continue to assert that deleted files were examined. Root cause: The refresh path never reconciles the file ledger against the working tree. detect_changes inner-joins the commit-range diff against file_ledger, so paths added since the baseline match no row and are silently dropped; no ledger writer enumerates the tree; the scoping-to-structural invariant checks only that at least one ledger row exists; and no classification value or non-destructive tool can retire a row whose file was deleted.
Business context: Coverage completeness is the core product claim: the conspectus exists so a reader can trust that a 'mapped' subsystem was actually surveyed. Because the completeness signal is computed from survey status rather than from scope coverage, the dashboard reports full coverage in exactly the state where it is least true. Observed at 5694080 before this refresh: 197 of 422 tracked files (47%) carried no ledger row and 11 rows named files deleted in 3f3065d, while the dashboard reported 7 of 7 mapped and 0 stale. The drift accumulates silently across releases and is only visible to someone who reconciles the ledger by hand.
Primary files:
mcp-server/src/tools/git.ts:detect_changes@5694080mcp-server/src/tools/files.ts:add_files_to_scope@5694080mcp-server/src/invariants.ts:enforcePhasePrerequisites@5694080mcp-server/src/tools/subsystems.ts:reset_subsystem@5694080
§B03-2 · High · fixed
Symptom: The entire staleness surface is inert. detect_changes reports drift to its caller but persists none of it, get_stale_backlog always returns empty, clear_staleness has nothing to clear, and the dashboard's stale_entries is permanently 0 regardless of how far the conspectus has drifted from HEAD. Root cause: All staleness state lives in the entries table, and no server code path ever inserts a row into it. The only INSERT INTO entries in the repository is in materializer/test-readback.py, a test fixture. Every read and update of staleness therefore operates on a permanently empty table.
Business context: Staleness is the mechanism by which a living conspectus is supposed to admit that it has fallen behind the code. Because the gate can never turn red, the product's freshness claim is unfalsifiable: a conspectus 23 commits and 197 unclassified files behind HEAD reports the same clean dashboard as one surveyed at HEAD this minute. This is a zero-denominator green — the gate passes because nothing can ever populate it, not because the state is healthy. It also masks B03-1: the reviewer sees stale_entries 0 and has no signal prompting a manual reconciliation.
Primary files:
mcp-server/src/schema.sql:entries@5694080mcp-server/src/tools/git.ts:detect_changes@5694080mcp-server/src/tools/dashboard.ts:get_dashboard@5694080mcp-server/src/tools/stale.ts:clear_staleness@5694080
§B03-3 · Medium · fixed
Symptom: A disposition whose strongest supporting evidence is test-observed, config-asserted, or doc-asserted cannot record that quality; set_disposition rejects the value, forcing the agent to overstate it as code-verified or understate it as contract-stated. Root cause: The EVIDENCE_QUALITY enum in tools/dispositions.ts lists five values while the KINDS enum in tools/evidence.ts lists nine, and the B-01 methodology contract publishes an eight-rung ladder as the authoritative evidence-quality scale. The two vocabularies were allowed to diverge, and nothing checks them against each other or against the published contract.
Business context: The methodology names overstating evidence quality as the single most common way it fails, and the evidence ladder is the mechanism meant to prevent that. Here the substrate makes the rule unfollowable in exactly the case that matters most — an agent that actually ran a test and wants to say so. The bias is systematic and one-directional in practice: code-verified is the nearest acceptable value and reads as stronger, so executed-test evidence is silently promoted to code-read evidence across the corpus. Because dispositions are the primary durable record of concern verdicts, this corrupts the quality signal a later reader uses to decide how far to trust a verdict.
Primary files:
mcp-server/src/tools/dispositions.ts:EVIDENCE_QUALITY@5694080mcp-server/src/tools/evidence.ts:KINDS@5694080.claude/skills/amanuensis/SKILL.md:evidence kind ladder@5694080
§B03-4 · Low · confirmed-bug
Symptom: A scoped file whose content is identical to what was examined can be reported stale indefinitely, because staleness is decided by whether its path appeared in a commit range rather than by whether its content changed. Root cause: The drift predicate in detect_changes tests path membership in the lastSha..currentSha diff and only null-checks the row's ref_sha, never comparing content at that commit against the current one. Nothing clears stale except an explicit clear_staleness, so a path touched and reverted — or touched on a branch later deleted — remains flagged against unchanged content.
Business context: The failure is conservative — it over-reports obligation and never under-reports, so unlike B03-2 it cannot manufacture false confidence, and a reader acting on it re-examines a file that did not need it. It matters because the metric it inflates is the headline repair of this release: the commit that introduced the exemption filter is titled 'Count staleness as obligation, not as churn', and the count is still partly churn. Two such rows exist on this repository at adc4ce0 from a probe branch that no longer exists. Making ref_sha load-bearing also needs a reachability fallback, since clear_staleness can store a sha that later becomes unreachable.
Primary files:
mcp-server/src/tools/git.ts:detect_changes@adc4ce0
§Seams
§Survey notes
- Survey revision:
b8b566f - Status: adversarial pass complete; packaging pending
§Key types
ToolDefinition couples a tool name, JSON input schema, description, and synchronous handler (mcp-server/src/helpers.ts:ToolDefinition@b8b566f). Tool families expose project/session, Git state, subsystem/file scope, concerns/dispositions/evidence/findings, seams, artifacts/materialization, diagnosticity, dispatch/reconciliation, logging, and comparison (mcp-server/src/index.ts:allTools@b8b566f).
§State containers
Handlers share B-02's ServerContext and write normalized SQLite tables. Important lifecycle state includes artifact content hashes, advisory write locks, open questions, dispatch/land/scored rows, and evidence link tables (mcp-server/src/schema.sql:artifacts@b8b566f; mcp-server/src/schema.sql:open_questions@b8b566f).
§Data flows
- Session and scope tools authorize a phase and establish the file ledger.
- Evidence is inserted independently, then linked to dispositions/findings by role.
- Status transitions query durable prerequisites before granting deeper claim authority.
materialize_docsinvokes B-04 against the same storage directory and returns a structured summary.- Dashboard/comparison tools read the record without mutating claim authority.
Evidence: mcp-server/src/tools/evidence.ts:add_evidence@b8b566f; mcp-server/src/tools/dispositions.ts:set_disposition@b8b566f; mcp-server/src/tools/materialize.ts:materialize_docs@b8b566f.
§Concurrency model
Handlers are synchronous inside one Node process. SQLite supplies database locking across processes; artifact locks are explicit rows. materialize_docs is a blocking child process with no timeout in the handler (mcp-server/src/tools/materialize.ts:materialize_docs@b8b566f).
§Seam contracts
§Concern review
All active concerns are terminally covered. The unbounded materializer child is retained as an unresolved competition pending fault injection rather than assigned severity from code shape alone. The WAL/Git phase-gate defect is owned and confirmed in B-02. Tool schema validation and SQL-identifier checks are compensating mechanisms for SC-1/TR-1.
§Adversarial review
The pass looked for handlers that could write higher-depth claims without a session or subsystem state. The principal write paths call requireActiveSession, and dispositions/findings additionally call requireSubsystemStatus; tests deliberately exercise premature writes (mcp-server/src/invariants.ts:requireSubsystemStatus@b8b566f; mcp-server/test-invariants.mjs:knowledge-depth cases@b8b566f). Verdict: upheld for covered handlers; schema-wide coverage remains enforced by the inventory/check scripts rather than inferred.