Skip to main content
╔════════════════════════════════════════════════════════════════════════════════════════════╗
║                                                                                            ║
║                         ███████╗ █████╗ ██╗   ██╗██████╗  ██████╗                          ║
║                         ██╔════╝██╔══██╗╚██╗ ██╔╝██╔══██╗██╔═══██╗                         ║
║                         ███████╗███████║ ╚████╔╝ ██║  ██║██║   ██║                         ║
║                         ╚════██║██╔══██║  ╚██╔╝  ██║  ██║██║   ██║                         ║
║                         ███████║██║  ██║   ██║   ██████╔╝╚██████╔╝                         ║
║                         ╚══════╝╚═╝  ╚═╝   ╚═╝   ╚═════╝  ╚═════╝                          ║
║                                                                                            ║
║                               does the tool do what it says                                ║
║                                                                                            ║
╚════════════════════════════════════════════════════════════════════════════════════════════╝

Does the tool do what it says? Not is it safe, not is it good. A publisher declares what an MCP tool does in a signed contract; SayDo runs the tool in a sandbox, checks it against that contract, and emits a hash-chained receipt anyone can verify in a browser with no account and no trust in the issuer.

The MCP server

pip install "saydo[mcp]"
saydo-mcp

Four tools, and the first one is a refusal:

tool answers
scope what SayDo cannot settle. Call it first.
status whether a package has a receipt, and what that receipt establishes
inspect_definition the RFC 8785 tool digest, and wording aimed at the model rather than at a reader
check_now run a package in a sandbox and report what it did

Most packages have no receipt, so the usual answer is unknown. That keeps meaning nobody has looked. It never softens into probably fine.

What a verdict can be

pass          the declared behaviour held under the run
fail          the tool did something it declared it would not
not-covered   the run established nothing either way

A whole run resolves to CONFORMANT, NOT CONFORMANT, or INCONCLUSIVE.

INCONCLUSIVE carries most of the weight. A server that declines every call makes no network request the way an unplugged machine makes none, and a harness that scores that as three passes has certified nothing at all. A negative claim passes here only if the run observed the tool actually doing something.

What this is not

It is not a safety guarantee and no receipt should be presented as one. It says what one version of one tool did on one run, against a contract its author wrote beforehand. Drift detection and hash-chained receipts are not novel; the repository names the prior art rather than claiming otherwise.

check_now needs Docker and the repository, and refuses plainly when it does not have them rather than running something weaker and reporting it as a sandboxed result.

Source, specification, the browser verifier, and the seeded fixtures that exist to prove the harness can fail: https://github.com/vince-gonzalez/saydo


╔════════════════════════════════════════════════════════════╗
║                                                            ║
║      ███████╗      ██╗  ██╗███████╗██╗   ██╗███████╗       ║
║      ██╔════╝      ██║ ██╔╝██╔════╝╚██╗ ██╔╝██╔════╝       ║
║      █████╗  █████╗█████╔╝ █████╗   ╚████╔╝ ███████╗       ║
║      ██╔══╝  ╚════╝██╔═██╗ ██╔══╝    ╚██╔╝  ╚════██║       ║
║      ██║           ██║  ██╗███████╗   ██║   ███████║       ║
║      ╚═╝           ╚═╝  ╚═╝╚══════╝   ╚═╝   ╚══════╝       ║
║                                                            ║
║               ·   C  R  E  A  T  I  V  E   ·               ║
║                                                            ║
║          ────────────────────────────────────────          ║
║                                                            ║
║                      Vincent Gonzalez                      ║
║                         f-keys.com                         ║
║                 ORCID 0009-0005-3640-014X                  ║
║                                                            ║
╚════════════════════════════════════════════════════════════╝

Part of F-Keys — independent hardware, software and internet products.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

saydo-0.1.0.tar.gz (123.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

saydo-0.1.0-py3-none-any.whl (137.2 kB view details)

Uploaded Python 3

File details

Details for the file saydo-0.1.0.tar.gz.

File metadata

  • Download URL: saydo-0.1.0.tar.gz
  • Upload date:
  • Size: 123.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for saydo-0.1.0.tar.gz
Algorithm Hash digest
SHA256 640a57e072cefd2c792fa97403b3960d6bcec8478d39a6f0655223425b329b3b
MD5 55320423c9f0268f63cec06ec44ea3dd
BLAKE2b-256 76efbd2fd74309634a03597e58f89c189e57a52b20e21d966bd5a415bfa524d6

See more details on using hashes here.

File details

Details for the file saydo-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: saydo-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 137.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for saydo-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 429a4a524a7b9e203fb491a384fa16d39166103828c6410c2d7d0859d4f62319
MD5 130a34e8bcf431a7dc86d8759b76d358
BLAKE2b-256 c12e01184f52c94d6f731112e2d928d1135bf5257a32e5912acccef87ad3b050

See more details on using hashes here.

Release history Release notifications | RSS feed

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page