Skip to content

feat: September content update, Chinese edition, and he/ja sync - #8

Open
Michael Lugassy (Michael-Lugassy-Forter) wants to merge 12 commits into
mainfrom
sep-updates
Open

Michael Lugassy (Michael-Lugassy-Forter) wants to merge 12 commits into
mainfrom
sep-updates

Conversation

@Michael-Lugassy-Forter

@Michael-Lugassy-Forter Michael Lugassy (Michael-Lugassy-Forter) commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

asana: https://app.asana.com/1/7840801737159/project/23095211578528/task/1213001508748468?focus=true

What does this PR change?

The September update to the guide: tracks the MCP 2026-07-28 revision across the guidelines and audit rubrics, adds a section on the 2026 generation of persistent personal agents, ships the Simplified Chinese edition, and brings the Hebrew and Japanese editions back in sync with English.

Which guideline(s) are affected?

Content: 1.4, 3.1, 3.2, 3.3, 4.3, 4.4, 4.5, 4.6, 4.8, 5.1, 5.2, 5.3, plus the introduction.
Audit rubrics: m1-2, m1-3, m1-4, m2-3, m4-2, m4-6, m5-2.

Note when comparing audits: m1-3's weight_total moves 11 -> 12, so m1-3 scores are not comparable to reports generated before this release.

Editions

  • content/zh/ is new: 32 files, the Simplified Chinese edition.
  • content/he/ and content/ja/ gain the whole 2026-07-28 body of work plus older drift they were carrying (the Apps-SDK submission flow in m5-1, four documentation steps in m2-3, two steps in m3-2, single steps in m2-2, m2-4 and m5-4).
  • Structure, cross-references, URLs, frontmatter and scoring bullets now match English file by file across all three editions.

The Hebrew RTL layout and the Chinese line-breaking have not been reviewed by a native speaker or checked in the rendered PDF - worth doing before this is published.

Supersedes

PR #7 (add-changelog) - its commits are already in this branch via the merge at 5faf018.

Checklist

  • H1 matches title in frontmatter
  • All required body sections present and in order (What & why, Scoring, Steps, References, optionally How Forter helps)
  • forterApplies and How Forter helps are in sync
  • Every #guideline-M-N cross-reference points to an existing guideline
  • References include at least one canonical source per claim

The MCP 2026-07-28 revision landed three weeks after the v1.1 content
freeze and made the protocol stateless, which left the audit probes
scoring compliant servers as failures.

Audit:
- Rewrite m4-4, m5-2 and m5-4 probes as dual-era clients: try
  server/discover with per-request _meta first, treat -32022 as a modern
  server, fall back to initialize only for 2025-11-25 and earlier.
- Drop Mcp-Session-Id handling; sessions no longer exist.
- m4-4 weight_total 9 -> 10 for a stateless-conformance sub-check, so
  m4-4 scores are not comparable to reports generated before this change.
- m5-2 now reads the Apps capability from the io.modelcontextprotocol/ui
  extension, with the old experimental.apps path as fallback.

Content:
- 4.4: statelessness, server-minted handles, cacheable list results,
  deterministic tool ordering, and the sampling/roots/logging/HTTP+SSE
  deprecations.
- 4.3: Tasks extension; SSE resumability removed, so idempotency keys are
  now load-bearing.
- 3.1/3.3: prefer Client ID Metadata Documents over deprecated RFC 7591
  DCR; add RFC 9207 issuer validation and issuer-bound credentials.
- 4.6: document the Agent Skills standard and the
  /.well-known/agent-skills/index.json index, which audit/m4-6 already
  scored but the guide never told readers to publish.
- 4.5: WebMCP impact deliberately held at 3 - the surface is deployed by
  default at Shopify and Cloudflare, but no mainstream agent calls it yet.
- 3.2, 4.8, 1.4: refresh Web Bot Auth draft pins, x402 governance and
  AGENTS.md governance.

Translations (he/ja/zh) intentionally not updated in this pass.
Both branches introduced CHANGELOG.md independently. Resolved in favour of
this branch's copy, which is a strict superset: it carries the same v1.0 and
v1.1 entries, adds v1.2, and corrects the v1.0/v1.1 dates from 2025 to 2026
to match their commits (1b86a8d on 2026-06-10, b3e1589 on 2026-07-06).
Covers the 4.3 Tasks extension and SSE resumability removal, the 4.5 / 3.2 /
4.8 / 1.4 status refreshes, and the m4-4 weight_total 9 -> 10 change that makes
m4-4 scores non-comparable across releases. Dates the entry 2026-09-16 to match
the PDF footer stamp.
Reference lists should be bare link titles. Removes the parenthetical and
em-dash expansions appended to 13 bullets across 9 guidelines, including one
that predated this branch (RFC 9421's "the alg label is ed25519" in 3.2).
Every fact removed is either already stated in the guideline's prose or
visible at the linked source.
…e doc

m3-1 and m3-3 scored client registration solely on a 7591 registration_endpoint,
so a server following the guide's new CIMD-first advice and omitting DCR would
fail a check the guide tells it to prefer. Both rows now pass on either
client_id_metadata_document_supported or registration_endpoint, and both probes
capture the CIMD field. m3-1 also captures the RFC 9207 iss flag.

SKILL.md still described m4-4 as probing initialize; it probes server/discover
with an initialize fallback.
Grok Bot (xAI, Aug 2026), Instinct (Spear Street Technology) and Muse (Meta,
Sep 2026) each run the user's agent on its own cloud machine that keeps working
with the laptop closed - persistent, proactive and asynchronous rather than
prompt-and-wait. Ties the shape to the guidelines it raises the bar on (4.3
long-running operations, 3.1 scoped OAuth, 4.4 MCP) and makes the fallback
argument explicit: absent these protocols all three drive the UI with a vision
model, so the real choice is the path they arrive through, not whether they come.
…v1.3

Name what the 2026 personal agents already ask for: Muse has approached
developers for their OpenAPI and MCP specs, and Grok Bot speaks MCP, with
the others falling back to screen scraping.

Split the changelog: v1.2 (2026-09-17) keeps the MCP 2026-07-28 tracking
work, rewritten shorter and without module numbers, and a new v1.3
(2026-09-21) covers the introduction's personal-agents section and the
audit additions.
Reviewing ora.ai's 125-check catalog against the guide surfaced checks we
had no equivalent for. The ones worth keeping belong in the audit rather
than the guide.

m1-3 gains a scored sub-check for whether a page can be driven through the
accessibility tree (real controls, accessible names, labelled fields, a
main landmark), plus weight-0 bonus rows for hidden-instruction injection
and trust anchor pages. weight_total moves 11 -> 12, so m1-3 scores are
not comparable to reports generated before this release.

Weight-0 bonus rows elsewhere, so existing scores stand: ARD trust
manifests and the canonical ard.json path (m1-2), Agent Plugins manifests
(m1-4), served-markdown hygiene (m2-3), agent-readable 404 bodies (m4-2),
branded registry entries (m4-6). m5-2 notes the view-origin framing rule
the ChatGPT and Claude sandboxes require.

Every new probe was run against a live site before landing.
scripts/validate.mjs gains a typography check across content/ (every
locale), audit/, report/ and the root docs, and now walks locale
subdirectories rather than only the top-level content/*.md.
32 files mirroring content/, following the zh glossary: guideline titles
and prose translated; ids, paths, URLs, protocol and brand names, code
blocks and utm parameters left verbatim.
…glish

Carries the MCP 2026-07-28 work into both editions: stateless servers and
server/discover, cacheable tool listings, the deprecation set, CIMD over
DCR, the authorization-exchange hardening, the Tasks extension, the Agent
Skills index, the official MCP Apps extension, WebMCP's actual status, and
x402 under the Linux Foundation. Both introductions gain the
personal-agents section.

Also clears older drift the two editions were carrying: the Apps-SDK
submission flow in m5-1, four documentation steps in m2-3, the WAF
category and outbound-agent steps in m3-2, and single missing steps in
m2-2, m2-4 and m5-4.

Consistency pass across all three editions: structure, cross-references,
URLs, frontmatter and scoring bullets now match English file by file.
Hebrew drops the discouraged rendering of "surface" and settles on one
term each for skill, cache and stateless.
@forter-mergatron-prime

forter-mergatron-prime Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

MergatronPrime blocked this PR (commit c61de74):

  • task-url: PR description must contain asana: <asana-url> or jira: <jira-url>.

@Michael-Lugassy-Forter Michael Lugassy (Michael-Lugassy-Forter) changed the title September update: MCP 2026-07-28, personal agents, Chinese edition, he/ja sync feat: September content update, Chinese edition, and he/ja sync Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants