# Public source test record

- Source: Model Context Protocol Ruby SDK
- Source version: fcb1ac935da20696085b27a869526bb89e7c2ced
- Input SHA-256: dfa30dec9e86ace8b50db7984e739662b57b4304aa709aa0fe710ed582e0c289
- Tested: 2026-08-22T09:00:08.000Z
- Test limit: the archive was read as data. No source file, Action package, dependency, or MCP server was run.

# AI Agent Surface Map

Project: modelcontextprotocol-ruby-sdk-fcb1ac9
Archive: modelcontextprotocol-ruby-sdk-fcb1ac9.zip
Generated: 2026-08-22T09:00:08.000Z

## Review summary

- High: 0
- Medium: 8
- Review: 0
- Information: 2
- MCP servers: 0
- GitHub workflows: 3
- Persistent instruction files: 2

## Findings

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: actions/checkout uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/ci.yml:22
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: ruby/setup-ruby uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/ci.yml:23
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: actions/checkout uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/conformance.yml:21
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: ruby/setup-ruby uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/conformance.yml:22
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: actions/setup-node uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/conformance.yml:26
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: actions/checkout uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/release.yml:19
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: ruby/setup-ruby uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/release.yml:21
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-203 | MEDIUM | Third-party action is not pinned to a full commit SHA

- Evidence: rubygems/release-gem uses a mutable reference.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/.github/workflows/release.yml:25
- Next review: Pin the action to a reviewed full-length commit SHA and record the human-readable version in a comment.

### AS-301 | INFO | Repository contains persistent agent instructions

- Evidence: An agent instruction or skill file can influence future tool use and code changes.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/AGENTS.md
- Next review: Review instruction provenance, allowed tools, external-content handling, and change ownership.

### AS-301 | INFO | Repository contains persistent agent instructions

- Evidence: An agent instruction or skill file can influence future tool use and code changes.
- Location: ruby-sdk-fcb1ac935da20696085b27a869526bb89e7c2ced/CLAUDE.md
- Next review: Review instruction provenance, allowed tools, external-content handling, and change ownership.

## Limits

- The archive is parsed as data. Source files, scripts, actions, packages, and MCP servers are never executed.
- Pattern matches and configuration presence are review signals, not proof of exploitation, malware, safety, or project quality.
- Runtime permissions, remote server behavior, branch protection, repository settings, dependency advisories, and commit provenance are not verified from an archive.
- Secret-like values are not included in the report. Remove private data before retaining or sharing any archive.
