Ships `rigorrun verify` — one command that verifies a published MCP server
against its own annotations, with no project, browser or agent. Pins the server
to the bytes the registry published, runs it in a container with no network and
no access to the machine, and measures isolation instead of reading it off a
flag.
And removes four things that claimed more than they had checked: a documented
gate that could not fail, a report that told its reader their own records were
fabricated, an isolation level that was never measured, and a recorder that
printed a next step which errors.