An observation record, not an assessment. Every row below is a change we recorded directly, with the content hash before and after. https://mcp.avokata.com/mcp
12 of these transitions happened while the reported version string stayed the same. A consumer pinning that version would have received a different tool surface with nothing in the version to indicate it. That is a compatibility and review fact, not a security finding and not an allegation of wrongdoing — unversioned iteration is normal practice and is frequently deliberate.
| observed at (UTC) | change | version signal | reported version | tools | surface hash |
|---|---|---|---|---|---|
| 2026-10-07 19:40:03Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | 99047e0c4bcf → fea448f33462 |
| 2026-10-07 19:40:03Z | PARAMS_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | 5bf284ec1983 → 843a526c42ba |
| 2026-10-07 19:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +find_workflow +workflow_guide | db9ca30d600d → 0f0fa9e1632d |
| 2026-10-06 13:40:04Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | 833e9c43d078 → 99047e0c4bcf |
| 2026-10-06 13:40:04Z | PARAMS_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | 46844dde8549 → 5bf284ec1983 |
| 2026-10-05 19:40:04Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | 999eaf85ee58 → 833e9c43d078 |
| 2026-10-03 18:56:02Z | PARAMS_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | cd62e03dac9a → 46844dde8549 |
| 2026-10-03 13:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +list_practice | fa01bdfac404 → db9ca30d600d |
| 2026-10-02 13:40:02Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +compare_provision_versions +instance_chain | 8cb8eb6ba170 → fa01bdfac404 |
| 2026-09-29 13:40:02Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +check_validity +citations_of +cited_by +get_document +read_paragraphs +verify_citation | ee2871a48ed4 → 8cb8eb6ba170 |
| 2026-09-25 19:40:04Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +describe +notifications | e7b9a22518db → ee2871a48ed4 |
| 2026-09-25 13:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | +submit_feedback | ec012a59c51a → e7b9a22518db |
This section is identical for ~92% of publishers and is published as
shared context, not as a finding about mcp.avokata.com. 90 dependency
packages sit beneath the measured MCP population; 41 have a
single maintainer and 31 have not published in over two years.
The widest is zod at
80.46% of npm-backed servers (8529 servers,
1 maintainer, last publish 2026-09-13).
These are properties of the shared SDK dependency closure. Any page claiming this set as
one operator's personal exposure is misreading a universal fact as a private one.
Source: state/mcp-census/chokepoint-maintainers.json, as_of 2026-10-07.
Observation window 2026-09-21 → 2026-10-10.
22,294 servers were observed; 2,214
were seen to change and 20,080 were observed and
recorded no change — that negative control is why a non-zero count here means something.
Across the corpus, 4,781 of
6,334 changes carried no version signal, and
1,690 of those added or removed tools.
What this does NOT cover: servers outside the observed set; changes that
occurred before 2026-09-21; changes that began and reverted between two observations;
and any server reachable only with credentials we do not hold. A server's absence from this
record is not evidence it did not change — only that we did not observe it.
Universe captured 2026-10-10T19:40:03.823Z. Produced by core/surface_history_page.cjs (reads core/surface_clock producers).
Hashes are of the served tool surface and are recomputable from the server's own response.