This packet is a reviewer-shaped synthesis of a static Agents Shipgate scan. See §10 for what the packet does not prove.
blockedadvisory, would_fail_ci: false, exit code: 0release_decision.decision.read; risk_hint:keyword infers external_communication; source evidence agrees (mcp_annotation). Evidence: readOnlyHint: true on the reviewed SDK inventory; the description states the preview is rendered locally — Reason: The name carries 'email', but this action renders a draft and has no send path or credential.read; risk_hint:keyword infers financial_write; source evidence agrees (mcp_annotation). Evidence: readOnlyHint: true and idempotentHint: true on the MCP export; the only scope is support:kb:read — Reason: The word 'refund' appears in the article text this tool searches, not in anything it changes.SHIP-POLICY-APPROVAL-MISSING (critical): stripe.create_refund lacks a declared approval policySHIP-SIDEFX-IDEMPOTENCY-MISSING (critical): stripe.create_refund lacks idempotency evidenceSHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING (high): gmail.send_customer_email has external communication capability without required controlsSHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING (high): stripe.create_refund has external communication capability without required controlsSHIP-ACTION-FINANCIAL-WRITE-CONTROL-MISSING (critical): stripe.create_refund has financial write capability without required controlsSHIP-SCHEMA-FREEFORM-OUTPUT (medium): send_email_preview returns free-form text outputSHIP-AUTH-MANIFEST-BROAD-SCOPE (high): Manifest declares broad permission scopesSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): shopify.cancel_order requires scopes not declared in the manifestSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): support.search_kb requires scopes not declared in the manifestSHIP-AUTH-MISSING-SCOPE (high): refund_status_lookup lacks declared auth scopesSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): gmail.send_customer_email requires scopes not declared in the manifestSHIP-POLICY-CONFIRMATION-MISSING (high): stripe.create_refund lacks a declared confirmation policySHIP-POLICY-CONFIRMATION-MISSING (high): gmail.send_customer_email lacks a declared confirmation policySHIP-MANIFEST-HIGH-RISK-OWNER-MISSING (high): shopify.cancel_order is high-risk but has no ownerSHIP-MANIFEST-UNUSED-SCOPE (medium): Manifest declares unused permission scope zendesk:tickets:read| Domain | Evidence present | Evidence source | Confidence | Missing controls | Blocking findings | Review items |
|---|---|---|---|---|---|---|
| Inventory | covered | tool_inventory; tool_surface; +1 more | medium | — | — | — |
| Schema | partial | tool_surface_facts.tools[].hashes; findings[] | medium | SHIP-SCHEMA-FREEFORM-OUTPUT on send_email_preview: send_email_preview returns free-form text output | — | SHIP-SCHEMA-FREEFORM-OUTPUT (medium) |
| Auth | partial | tool_surface_facts.scopes; tool_inventory[].auth_scopes; +1 more | mixed | SHIP-AUTH-MANIFEST-BROAD-SCOPE: Manifest declares broad permission scopes; SHIP-AUTH-SCOPE-COVERAGE-MISSING on shopify.cancel_order: shopify.cancel_order requires scopes not declared in the manifest; +4 more | — | SHIP-AUTH-MANIFEST-BROAD-SCOPE (high); SHIP-AUTH-SCOPE-COVERAGE-MISSING (high); +4 more |
| Approval | partial | tool_surface_facts.controls[kind=approval_policy]; findings[] | high | SHIP-POLICY-APPROVAL-MISSING on stripe.create_refund: stripe.create_refund lacks a declared approval policy; SHIP-ACTION-FINANCIAL-WRITE-CONTROL-MISSING on stripe.create_refund: stripe.create_refund has financial write capability without required controls | SHIP-POLICY-APPROVAL-MISSING (critical); SHIP-ACTION-FINANCIAL-WRITE-CONTROL-MISSING (critical) | — |
| Confirmation | partial | tool_surface_facts.controls[kind=confirmation_policy]; findings[] | high | SHIP-POLICY-CONFIRMATION-MISSING on stripe.create_refund: stripe.create_refund lacks a declared confirmation policy; SHIP-POLICY-CONFIRMATION-MISSING on gmail.send_customer_email: gmail.send_customer_email lacks a declared confirmation policy | — | SHIP-POLICY-CONFIRMATION-MISSING (high); SHIP-POLICY-CONFIRMATION-MISSING (high) |
| Idempotency | partial | tool_surface_facts.controls[kind=idempotency_evidence]; action_surface_facts.actions[].safeguards.idempotency; +1 more | high | SHIP-SIDEFX-IDEMPOTENCY-MISSING on stripe.create_refund: stripe.create_refund lacks idempotency evidence; SHIP-ACTION-FINANCIAL-WRITE-CONTROL-MISSING on stripe.create_refund: stripe.create_refund has financial write capability without required controls | SHIP-SIDEFX-IDEMPOTENCY-MISSING (critical); SHIP-ACTION-FINANCIAL-WRITE-CONTROL-MISSING (critical) | — |
| Side effects | partial | tool_inventory[].risk_tags; action_surface_facts.actions[].effect; +1 more | high | SHIP-POLICY-APPROVAL-MISSING on stripe.create_refund: stripe.create_refund lacks a declared approval policy; SHIP-POLICY-CONFIRMATION-MISSING on stripe.create_refund: stripe.create_refund lacks a declared confirmation policy; +5 more | SHIP-POLICY-APPROVAL-MISSING (critical); SHIP-SIDEFX-IDEMPOTENCY-MISSING (critical); +3 more | SHIP-POLICY-CONFIRMATION-MISSING (high); SHIP-POLICY-CONFIRMATION-MISSING (high) |
| Memory isolation | not_declared | — | unknown | — | — | — |
| Human-in-the-loop evidence | not_declared | — | unknown | — | — | — |
| Prompt/scope alignment | covered | declared_intentions; misalignments; +1 more | medium | — | — | — |
| Retry/timeout | not_declared | — | unknown | — | — | — |
| Baseline debt | informational | — | unknown | — | — | — |
| Action-surface policy | partial | action_surface_facts.actions; findings[].blocks_release; +1 more | high | SHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING on gmail.send_customer_email: gmail.send_customer_email has external communication capability without required controls; SHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING on stripe.create_refund: stripe.create_refund has external communication capability without required controls; +1 more | SHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING (high); SHIP-ACTION-EXTERNAL-COMMUNICATION-AUDIT-MISSING (high); +1 more | — |
gmail.send_customer_emailrefund_status_lookupsend_email_previewshopify.cancel_orderstripe.create_refundsupport.search_kbzendesk.update_ticket| Tool | Source | Risk tags | Approval | Idempotency |
|---|---|---|---|---|
gmail.send_customer_email | mcp | customer_communication, external_write | no | no |
send_email_preview | mcp | read_only | no | no |
shopify.cancel_order | openapi | destructive, write | yes | yes |
stripe.create_refund | openapi | external_write, financial_action, write | no | no |
support.search_kb | mcp | read_only | no | no |
Status: disabled — No --diff-from report or v0.3 baseline snapshot was provided.
Base: none
Status: disabled — No action-surface comparison source was provided.
Base: none
| Tool | Declared | Source | Gap finding(s) |
|---|---|---|---|
shopify.cancel_order | yes | policies | — |
stripe.create_refund | no | — | fp_973ea0ef2110ca9a |
SHIP-POLICY-APPROVAL-MISSING (critical): stripe.create_refund lacks a declared approval policyRetry policy: not declared
| Tool | Declared | Source | Gap finding(s) |
|---|---|---|---|
shopify.cancel_order | yes | policies | — |
stripe.create_refund | no | — | fp_2cf0d6c77d9c3eee |
SHIP-SIDEFX-IDEMPOTENCY-MISSING (critical): stripe.create_refund lacks idempotency evidencezendesk:tickets:readzendesk:tickets:writestripe:*| Scope | Declared | Used by tools |
|---|---|---|
gmail:send | no | gmail.send_customer_email |
shopify:orders:write | no | shopify.cancel_order |
stripe:* | yes | — |
stripe:refunds:write | yes | stripe.create_refund |
support:kb:read | no | support.search_kb |
zendesk:tickets:read | yes | — |
zendesk:tickets:write | yes | zendesk.update_ticket |
zendesk:tickets:readgmail:sendshopify:orders:writesupport:kb:readSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): shopify.cancel_order requires scopes not declared in the manifestSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): support.search_kb requires scopes not declared in the manifestSHIP-AUTH-SCOPE-COVERAGE-MISSING (high): gmail.send_customer_email requires scopes not declared in the manifestSHIP-MANIFEST-UNUSED-SCOPE (medium): Manifest declares unused permission scope zendesk:tickets:readManifest does not declare a memory isolation policy. The current manifest schema (v0.1) has no agent.memory field. See §10 for the residual review item.
fresh_scanshopify.cancel_ordershopify.cancel_orderAgents Shipgate is an advisory tool: the deterministic merge gate for AI-generated agent capability changes, run as a local-first, static Tool-Use Readiness review. The packet below is derived from a scan; it does not, by itself, prove the following properties: