Content Quality: Strong, well-structured spec report. Overview, What We Know (stateless core / Extensions-Tasks-MCP Apps / Authorization-deprecations), What We Don't Know, and Analysis are cleanly organized. Technical depth is appropriate and accurate; the article correctly distinguishes the 2025-11-25 baseline from the 2026-07-28 RC and explains the operational rationale (commodity HTTP infra, statelessness) without overclaiming.
Source Verification: All 3 snapshots fetched at status 200 and read from disk. source-0 (blog.modelcontextprotocol.io, the primary MCP blog): confirmed every technical specific — version string 2026-07-28, RC locked May 21 2026, final July 28 2026, ten-week validation window, Tier 1 SDKs expected to ship support; stateless core; Extensions framework first-class; Tasks graduated to an extension with task handle on tools/call driven by tasks/get, tasks/update, tasks/cancel and server-directed creation; MCP Apps as extension; six SEPs hardening authorization to align with OAuth 2.0 / OpenID Connect; SEP-2468 requiring iss validation per RFC 9207 as mix-up-attack mitigation; deprecation policy deprecating Roots, Sampling, Logging with the exact replacement mapping (tool parameters/resource URIs/server config; direct LLM provider API integration; stderr + OpenTelemetry). Byline lists David Soria Parra and Den Delimarsky as Lead Maintainers; the post carries no individual quotations, which the article states accurately. source-1 (aaif.io): confirmed 'directed fund under the Linux Foundation, co-founded by Anthropic, Block and OpenAI, with support from Google, Microsoft, Amazon Web Services, Cloudflare, and Bloomberg', plus goose and AGENTS.md, and the 'integrating LLM with external data & tools' description the Analysis paraphrases. source-2 (linuxfoundation.org press): corroborates AAIF formation and MCP membership.
Factual Accuracy: All five quote-marked spans verified verbatim against source-0 and each is attributed to the institutional 'Model Context Protocol Blog,' not to a person. Zero quote-marked statements are attributed to any individual; the two named maintainers appear only in the explicit note that the post contains no individual quotations. No fabricated specifics; all version strings, dates, and SEP/RFC identifiers (SEP-2468, RFC 9207, 2026-07-28, 2025-11-25) trace to the primary source. The /article/2026-03/03-... cross-reference resolves to an existing published article.
Overall Assessment: APPROVE. The script's default APPROVE_WITH_CORRECTIONS was driven solely by the non-blocking allowlist warning; manual source verification found nothing requiring correction. Every claim, quote, number, name, date, and identifier is supported by the committed snapshots and there are no orphan URLs. Verdict overridden to APPROVE; no corrections record is filed because there is no factual error to correct.