It snapshots a server’s tool surface into a deterministic mcp-lock.json, then lets you sign/verify (Ed25519 locally or Sigstore keyless in CI) and diff live servers against the approved lockfile to catch capability drift before agents run it.
Would love feedback on what should count as critical drift vs benign changes.