Skip to main content
╔════════════════════════════════════════════════════════════════════════════════════════════╗
║                                                                                            ║
║                         ███████╗ █████╗ ██╗   ██╗██████╗  ██████╗                          ║
║                         ██╔════╝██╔══██╗╚██╗ ██╔╝██╔══██╗██╔═══██╗                         ║
║                         ███████╗███████║ ╚████╔╝ ██║  ██║██║   ██║                         ║
║                         ╚════██║██╔══██║  ╚██╔╝  ██║  ██║██║   ██║                         ║
║                         ███████║██║  ██║   ██║   ██████╔╝╚██████╔╝                         ║
║                         ╚══════╝╚═╝  ╚═╝   ╚═╝   ╚═════╝  ╚═════╝                          ║
║                                                                                            ║
║                               does the tool do what it says                                ║
║                                                                                            ║
╚════════════════════════════════════════════════════════════════════════════════════════════╝

Does the tool do what it says? Not is it safe, not is it good. A publisher declares what an MCP tool does in a signed contract; SayDo runs the tool in a sandbox, checks it against that contract, and emits a hash-chained receipt anyone can verify in a browser with no account and no trust in the issuer.

The MCP server

pip install "saydo[mcp]"
saydo-mcp

Four tools, and the first one is a refusal:

tool answers
scope what SayDo cannot settle. Call it first.
status whether a package has a receipt, and what that receipt establishes
inspect_definition the RFC 8785 tool digest, and wording aimed at the model rather than at a reader
check_now run a package in a sandbox and report what it did

Most packages have no receipt, so the usual answer is unknown. That keeps meaning nobody has looked. It never softens into probably fine.

What a verdict can be

pass          the declared behaviour held under the run
fail          the tool did something it declared it would not
not-covered   the run established nothing either way

A whole run resolves to CONFORMANT, NOT CONFORMANT, or INCONCLUSIVE.

INCONCLUSIVE carries most of the weight. A server that declines every call makes no network request the way an unplugged machine makes none, and a harness that scores that as three passes has certified nothing at all. A negative claim passes here only if the run observed the tool actually doing something.

What this is not

It is not a safety guarantee and no receipt should be presented as one. It says what one version of one tool did on one run, against a contract its author wrote beforehand. Drift detection and hash-chained receipts are not novel; the repository names the prior art rather than claiming otherwise.

check_now needs Docker and the repository, and refuses plainly when it does not have them rather than running something weaker and reporting it as a sandboxed result.

Source, specification, the browser verifier, and the seeded fixtures that exist to prove the harness can fail: https://github.com/vince-gonzalez/saydo


╔════════════════════════════════════════════════════════════╗
║                                                            ║
║      ███████╗      ██╗  ██╗███████╗██╗   ██╗███████╗       ║
║      ██╔════╝      ██║ ██╔╝██╔════╝╚██╗ ██╔╝██╔════╝       ║
║      █████╗  █████╗█████╔╝ █████╗   ╚████╔╝ ███████╗       ║
║      ██╔══╝  ╚════╝██╔═██╗ ██╔══╝    ╚██╔╝  ╚════██║       ║
║      ██║           ██║  ██╗███████╗   ██║   ███████║       ║
║      ╚═╝           ╚═╝  ╚═╝╚══════╝   ╚═╝   ╚══════╝       ║
║                                                            ║
║               ·   C  R  E  A  T  I  V  E   ·               ║
║                                                            ║
║          ────────────────────────────────────────          ║
║                                                            ║
║                      Vincent Gonzalez                      ║
║                         f-keys.com                         ║
║                 ORCID 0009-0005-3640-014X                  ║
║                                                            ║
╚════════════════════════════════════════════════════════════╝

Part of F-Keys — independent hardware, software and internet products.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

saydo-0.1.1.tar.gz (123.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

saydo-0.1.1-py3-none-any.whl (137.4 kB view details)

Uploaded Python 3

File details

Details for the file saydo-0.1.1.tar.gz.

File metadata

  • Download URL: saydo-0.1.1.tar.gz
  • Upload date:
  • Size: 123.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for saydo-0.1.1.tar.gz
Algorithm Hash digest
SHA256 0b45b8b36a8607b96fd7ad36d762060885071e28a45f8cb468c0436a931e29b2
MD5 4acb86459095a0b7c5c2cc7aff47cafe
BLAKE2b-256 e8346923a8db7f0d873f5edcad8bd6f57cd21b3a855369da97c20e5fe1f378c7

See more details on using hashes here.

File details

Details for the file saydo-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: saydo-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 137.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for saydo-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 795b637239e58e59917258f5bcda952eab8545338f3cce1128b9add7aedb8c5d
MD5 f8b6b28a307336fc73a1923f6906b215
BLAKE2b-256 596660b060ffc77ba5a51e1c82b7afb1e2f3bbb988e3344cf3a9eb18883c22fd

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page