An observation record, not an assessment. Every row below is a change we recorded directly, with the content hash before and after. https://recipebooq.com/api/mcp
8 of these transitions happened while the reported version string stayed the same. A consumer pinning that version would have received a different tool surface with nothing in the version to indicate it. That is a compatibility and review fact, not a security finding and not an allegation of wrongdoing — unversioned iteration is normal practice and is frequently deliberate.
| observed at (UTC) | change | version signal | reported version | tools | surface hash |
|---|---|---|---|---|---|
| 2026-10-05 19:40:04Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.3.0 (unchanged) | no tool-name change recorded | bfbac67954f6 → 136faf671d17 |
| 2026-10-04 07:40:03Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.3.0 (unchanged) | no tool-name change recorded | 8a4dda085278 → bfbac67954f6 |
| 2026-10-04 01:12:58Z | DESCRIPTION_CHANGED | SILENT — version string did not move | 0.3.0 (unchanged) | no tool-name change recorded | 0b2fb6886b5e → 8a4dda085278 |
| 2026-10-03 18:56:02Z | PARAMS_CHANGED | SILENT — version string did not move | 0.3.0 (unchanged) | no tool-name change recorded | 1cbdb86dd9df → 2dce2280d58d |
| 2026-10-02 01:40:04Z | PARAMS_CHANGED | SILENT — version string did not move | 0.3.0 (unchanged) | no tool-name change recorded | — |
| 2026-10-01 13:40:04Z | SURFACE_CHANGED | version-signalled | 0.2.1 → 0.3.0 | +get_app_setup −emit_screen −get_provider_tree −get_rules −get_step −get_theme_tokens −list_components | cc1edbdd8509 → 2cf62f291c3a |
| 2026-09-30 01:40:03Z | SURFACE_CHANGED | SILENT — version string did not move | 0.2.1 (unchanged) | +propose_app +propose_screen | 7c9efcb64666 → cc1edbdd8509 |
| 2026-09-29 19:40:03Z | PARAMS_CHANGED | SILENT — version string did not move | 0.2.1 (unchanged) | no tool-name change recorded | — |
| 2026-09-26 01:40:03Z | PARAMS_CHANGED | SILENT — version string did not move | 0.2.0 (unchanged) | no tool-name change recorded | — |
This section is identical for ~92% of publishers and is published as
shared context, not as a finding about recipebooq.com. 90 dependency
packages sit beneath the measured MCP population; 41 have a
single maintainer and 31 have not published in over two years.
The widest is zod at
80.46% of npm-backed servers (8529 servers,
1 maintainer, last publish 2026-09-13).
These are properties of the shared SDK dependency closure. Any page claiming this set as
one operator's personal exposure is misreading a universal fact as a private one.
Source: state/mcp-census/chokepoint-maintainers.json, as_of 2026-10-07.
Observation window 2026-09-21 → 2026-10-10.
22,294 servers were observed; 2,214
were seen to change and 20,080 were observed and
recorded no change — that negative control is why a non-zero count here means something.
Across the corpus, 4,781 of
6,334 changes carried no version signal, and
1,690 of those added or removed tools.
What this does NOT cover: servers outside the observed set; changes that
occurred before 2026-09-21; changes that began and reverted between two observations;
and any server reachable only with credentials we do not hold. A server's absence from this
record is not evidence it did not change — only that we did not observe it.
Universe captured 2026-10-10T19:40:03.823Z. Produced by core/surface_history_page.cjs (reads core/surface_clock producers).
Hashes are of the served tool surface and are recomputable from the server's own response.