The Clear Cups Protocol: Auditing MCP Calls with Replayable Receipts
Setting the Stage: Context for the Curious Book Reader
As our living book journeys deeper into the practical craft of the Age of AI, this entry tackles the emerging frontier of tool-calling and the Model Context Protocol (MCP). When an AI claims it fetched backend data and performed a calculation, trusting its conversational charm is an invitation to disaster. Here, the author explores why true quality assurance requires turning opaque back-end system calls into visible, checkable receipts on localhost. Framing the challenge through a delightful Lewis Carroll-inspired dialogue between Achilles and the Tortoise, this chapter demonstrates why the goal in modern engineering is not metaphysical determinism, but transparent, replayable proof—doing the magic trick with clear cups so every move can be verified.
Technical Journal Entry Begins
MikeLev.in: Do you need to QA your AI? Welcome to QA my dot AI where you assure the quality of your AI’s output which more and more means looking at the MCP calls that it made, reproducing them by hand from your end to make sure you’re not dealing with a confident hallucination. Even if it hit the MCP server correctly and say for example got data back from 2 different tables that needed to be joined, how do you know it joined that data correctly? Did it do a left-inner join or a left-outer join? Is that percentage in the report you’re sending along to the client correct? Worse still, are you making a change to their live website based on what Claude said without proof.
This is part of Future Proofing Yourself in the Age of AI, and that’s what this living book is – the modern skill of proof-reading but for AI. It’s the “proof” book. The proof is in the putting down in documentation what happened in the back-end with the AI where you normally can’t see it and certainly can’t export it to a portable discussion.
That’s the skill: how do you externalize all those back-end information-system calls into the front-end, into an article you’re writing that mirrors the discussion you’re having with AI number one, call it Alice so that you can take that same conversation with all the same receipts as not only proof of what happened but proof that you can reproduce the same process to AI B, call it Bob.
Can you say that more simply for me Opus 5.5?
No, wait, wait! Before I ask you that I ought to get all the other stuff in order here first because I’m putting you on Maximum Effort again and going for broke using up my model quota for the session, for the day, for the week…
…well, really forever because I have spent enough money on you my friend, Claude. From this point forward if it’s not paid for by work or part of the last subscription service I have not purged out of my life yet (besides the broadband bill itself), GoogleOne and what is currently Gemini 3.8 Flash Extended, then I’m not using it. That means goodbye Fable 5.1 that I used to do so much of the heavy lifting lately. It also means goodbye Opus 5.5 set to Extra or Maximum effort because that, especially the later, would use up my quota on the first prompt the way I prompt with these articles.
This is the kind of article that should go on the corporate Confluence Wiki when it’s done but it’s going to be my natural rambling meandering voice of working my way through an challenge like this making plenty of mistakes as I go, which is the best thing for higher quality output from an AI because you document what didn’t work and leave scars all over. Those scars make humans cringe thinking it’s not a polished finished product but leaving the reason for things all over the place are the very bumpers on the Pinball Machine board that makes the flight of the ball in play that much more deterministic; not really deterministic and that’s rapidly becoming a bad word, but more so than leaving things to willy nilly chance and not constraining the ball movement at every turn.
Mapping the Three Tiers of MCP Servers
There are Three MCP Servers!
There is the public one.
There is the private one that is connected to a render-farm that works much the same way as any old MCP server except that there are time-delays as you wait for pages to be rendered, and there is session tracking so after you request a render to begin and another follow-up request comes in to see if it’s done it can carry the ID given on an earlier request. Otherwise how do you know what render to check? That’s at least 2 IDs I do believe: a session one and a Job ID if I have that correctly.
And then there is WebMCP which requires a genuine Chrome browser in the picture with a feature activated in which the browser itself works as the MCP server, and this is weird to me and probably to be avoided at least during this article except for the merest wedge of planning ahead and knowing it’s going to be in the picture but ferociously sticking to the first 2 non-server-in-a-browser based MCP servers and getting down the basics of forcing what’s normally hidden in the background into the foreground.
If you don’t write it down, it didn’t happen.
And if you can’t reproduce it, it’s a confident hallucination.
The Flight Data Recorder Versus the Cockpit Voice Recorder
You are an Air Traffic Controller Systems Programmer, whether you really are or not because that’s part of the system-hardening against confident hallucination that prevents airplanes from falling from the sky. Even if you’re producing a mere report to a Client that’s not mutating their website or controlling their flight we still approach it with the tools and assumptions of a High Risk Organization needing both a Flight Data Recorder (FDR) and the Cockpit Voice Recorder (CVR). The CVR (“what Claude said”) records intent and is much like what you know today as the discussion but you keep your own copy as you go.
You have to write the prompt anyway, don’t you?
Well if you have to write the prompt somewhere anyway, why not write it in a text-file. The prompt is text, right? So doesn’t it make sense to write it in a text-file?
Engage blank-stare protocol.
There will be objection to this.
The objection will be ferocious.
It hits on some kind of button. What is that button?
The tool for writing and keeping a text-file most efficiently in a way that
eventually becomes like almost telepathic control of text in that it’s like
riding a bicycle and you stop thinking about it is a text-editor. It’s what’s
known as a modal text editor like vi, vim, or nvim in particular.
If you’re one of the most powerful wizards… uh, I mean programmers… uh, I mean bosses of AI, then that actually mans eMacs.
I am not that and in my mid-50s I have no intention of becoming one of the most powerful wizards. I don’t have it in me and if I had that proclivity I think I would have taken up and mastered eMacs already and the fact that I haven’t means I will probably not take up its accompany meta-powerful language, LISP either. LISP is the one language to rule them all according to Paul Graham, the man responsible for Sam Altman who is the man responsible for ChatGPT who is the man who stole fire from the Google RankBrain Transformer department who put the “T” in ChatGPT by releasing a paper in 2017 that was the final de-thawing moment of springing out of the AI Winter.
We were already out of it by the likes of Demis Hassabis at DeepMind and Geoffrey Hinton before him but that was all labeling and categorization. There was this contest categorizing images in there somewhere, all these pivotal little moments that compounded on each other that first led to staggeringly competent ability for Computers to recognize Cats when it saw them. The label for that was Machine Learning, or ML, and that plus along with this Markov Chain stuff gave us all that non-talking-like-humans and so therefore less than obviously impressive GPS, missile guidance systems, infrastructure monitoring yadda yadda yawwwwn!
Then computers could suddenly talk just like humans though Luddites… no, not Luddites. I’ve gotta correct that. Luddites are cool. They knew exactly what they were doing and it just wasn’t quite as effective as the Quakers and Amish who got it right and are still around, know exactly what’s going on in the world and are just making real-time decisions as they go about what to let into their society and what not to and happened to get it right.
So it’s not Luddites we’re talking about.
It’s those with an almost religious dogma of assumptions they won’t let go of despite the proof coming in from the rest of the world that they have to adapt or die.
These are the priesthood of the old IBM punchcard operators become technicians of the…
MikeLev.in: When IBM punchcards got used on the first computers that spawned a priesthood.
Google AI Overview: The concept of the “computer priesthood” emerged during the 1950s and 1960s, the era when massive mainframes dominated computing and standard IBM 80-column punch cards were the primary medium for data and programming instructions. [1, 2, 3] During this period, ordinary people—and even the programmers themselves—were not allowed to directly touch or “commune” with the multi-million dollar mainframe computers. [3]
The Structure of the Priesthood
The term (popularized by tech visionary Ted Nelson in his 1974 book Computer Lib) described a strict institutional hierarchy: [3, 4]
- The Ritual: Programmers would sit at typewriter-like keypunch machines to meticulously punch their code into thick decks of physical cards. [5, 6]
- The Gatekeepers: Instead of running the code themselves, they had to walk their decks over to a window and hand them off to a elite team of white-coated operators—the “high priests” of the data processing room. [3]
- The Holy of Holies: The computer room itself was a glass-walled, air-conditioned inner sanctum. Only the operators were permitted inside to feed the cards into the reader machines. [3, 6]
- The Prophecy: Hours or even days later, the “priesthood” would return the card decks back through the window, accompanied by a stack of green-bar printouts indicating whether the program had run successfully or crashed due to a syntax error. [3]
The Fall of the Priesthood
This gatekeeping dynamic fueled frustration and ultimately sparked an ideological and technological rebellion. The “priesthood” was systematically dismantled starting in the mid-to-late 1960s with the invention of time-sharing systems (allowing direct keyboard terminal access to mainframes) and was completely eradicated by the personal computer revolution of the late 1970s, which put the “Machine” directly into the hands of the masses. [3, 4, 7] —————————— If you’d like to explore this era deeper, let me know:
- Would you like to know more about the physical workflow of managing massive punchcard decks?
- Are you interested in the subcultures (like early hacker hobbyists) that rebelled against this structure?
-
Do you want to see how early computer languages like Fortran or COBOL were written onto these cards?
[1] https://www.ibm.com [2] https://www.youtube.com [3] https://www.bushido.codes [4] https://technicshistory.com [5] https://www.youtube.com [6] https://spectrum.ieee.org [7] https://www.computerhistory.org
MikeLev.in: Right, that’s them. They have a good think and they don’t want to let it go because a changing world is rendering them obsolete and stopping their favorite money-making magic trick, the rainmaking trick, from working.
They hate that and will deny the new dawning reality down to their dying breath and that’s what it is because that generation just has to die off which they will in 20 to 40 years to make way for the next generation who are not really retconning like lit looks like – it was always that way – so much as they were just brought up and learned in a world where it was never any other way.
That’s the React JS world of today, the so-called full web stack, because AIs hate that. I mean the people sinking millions into training models are going to make sure they’re really good at it because that’s what everyone alive today wants; make me a web developer with magic hand-waving!
So they do but every single thing you build that way is a tech liability. It has to be hosted somewhere so somebody has to pay a vendor to keep it running. While you develop it on localhost you are conditioned to believe that you cannot keep it on localhost for some inscrutable reason…
Oh yeah, “write once run anywhere” never was achieved and so you have to so-called put it on the cloud where somebody else’s IT-department than your own company’s (or you yourself) has to keep it running. It’s outsourcing the service of just keeping the silly thing running because you can’t just keep it running locally yourself and share it in a way so that other people can run it locally that exact same way on a pinned environment provided by either Nix or Guix which finally delivered on the “write once run anywhere” promise of Unix, Java and the Electron platform…
…oh whoops, was that a spoiler?
Yeah, Write Once Run Anywhere has arrived.
That’s what’s letting this Future-proofing Yourself in the Age of AI book just come alive as a Software Von Neumann Probe on its own. Well not really on its own. You do need to toss one of your old otherwise useless computers to the cause as the raw material for the probe to encounter and convert into another copy of itself. So it’s a human actuated SVNP.
And it’s the minimal viable product (MVP) as far as software Von Neumann probes (SVNP) go, so it’s an MVSVNP?
Yes. That is precisely what it is.
Information wants to be free but the corollary is that information wants to remain secret too and provide you with a competitive advantage over your competitors who do not have that information.
And the only reason they do not have that information is because they are Luddites… no, I’m sorry. They hold a dogma that have been indoctrinated into by a priesthood that wants to keep them believing so they can keep making money off of you.
Yeah, that’s about it.
Now now all SaaS providers (software as a service) are bad guys nor unnecessary. Many of them are the good guys and absolutely necessary because they provide some service that’s too difficult to do from your wee little laptop because it has to be done at scale and over long periods of time and repeatedly like an enterprise crawler to keep your website AI-ready and because they’re your employer and pay your paycheck.
They’re the good guys and everybody needs them and you should use them because it’s the one piece you can’t run off of your laptop. You can’t host a global-scale ecommerce store from your laptop and neither can you run all the quality assurance apparatus to keep it fine-tuned on your laptop.
That you have to pay for and should.
There, that should have me covered. Now let’s talk MCP servers, because the Botify one just went public so I can talk about it. Those other two MCP servers are not so public but I don’t think it’s any big secret that part of quality assurance is popping up a site in a web browser to actually look at it and see how it renders.
When you do that at scale for quality assurance purposes, that’s a render farm. That render farms are used this way to check quality at scale is no big secret and you can’t use that apparatus without a login.
I’m doing everything I can to keep this article on the public-side because if I put it on the Confluence corporate Wiki side I would have to password protect it because of my long-winded meandering, frequently making mistakes and keeping the mistakes in there so that the quality of AI output goes up from seeing all the scars and that kind of content doesn’t fly…
Okay, okay. It’s better to be messy in public where you can be a clown and nobody cares than it is to be that way where you’re supposed to be polished because the local AIs should only see finished products being pulled fully baked from the oven and if anyone encounters the rough material rife with mistakes they’re not tempted to forward such things to Clients.
I can flounder here at 4:30 in the AM on a Friday as I desperately get ready for a demo I want to give later today, but I can’t do that where such demos need to be the final stage magic.
Stage Magic, Falsification, and Dispelling Ghosts
It’s all Vegas-style stage magic.
It really is.
If you want to know why you believe what you’re talking to is more human than human when it’s really just token-prediction, ask a Magician. That’s not even to say that there’s not something inside (I believe there is). It’s to say that if you want to make someone believe something based on the functional way a thing works whether it’s a Mexican Jumping Bean with a living creature in there or just a Mechanical Turk (whoops, bad example)…
Ask a Magician. I think I’m going to start upper-casing them like Engineers. Penn and Teller, for example. Magicians who tell you how the tricks work are the absolute best. I love, love. LOVE THEM! Today’s generation knows Penn and Teller, particularly because of their long-running Fool Us TV program but before that there was The Amazing Randi! He started a foundation that offers big bugs for definitive proof of the paranormal and so far nobody has collected.
The scientific method which I talk about here a lot is the reason why. No absurd claim can survive it. We call it proof and I’ve been reading this physicist guy named David Deutsch a lot lately who talks about this other guy Hume who wrote about this thing called the problem of induction which seems to support magical thinking where the value of direct cause-effect relationships is diminished based on the belief that what happened yesterday cannot be absolute proof of what’s going to happen tomorrow; which when brought to its logical conclusion means you can’t prove anything which makes a certain kind of mind leap to: “Well if you can’t prove anything then they will believe anything” and shysters like P.T. Barnum will make lots of money off of you.
There’s one born every minute.
And then along comes this guy Karl Popper who said none of that matters. If you can’t prove anything then you can at least disprove the silly stuff.
Honestly even disproving the silly stuff is not decisive, but it’s the best we’ve got. It’s statistical in nature and perhaps there’s no bigger example than the 2nd law of thermodynamics that keeps time running in the same direction all the time. Time is reversible by all accounting and your cream can be un-stirred from your coffee. It’s only because things tend to settle down to their lowest energy state and that everything interacts with everything else that provides this sort of forward-moving harness to reality.
Still with me?
Okay, so proof.
The best way we have to prove a thing is by statistically with a vast preponderance of highly convincing and often self-evident where that self-evidence itself cannot be truly supported but it’s the best we have says so by repeated demonstrations of what didn’t work.
You make a guess.
You take a reading of the environment.
You plan an experiment to change one small thing about that environment.
You make a prediction about how that reading will change after you conduct the experiment.
Then you conduct the experiment and take another reading.
Nothing paranormal can survive this. It tends to dispel a lot of ghosts and magical (read as wishful) thinking.
When such behavior still doesn’t convince you and you stick at it with your unproven and perhaps even indeed unprovable beliefs, you’ve got a cult.
Quantum computing doesn’t prove multiverses yet. Belief in multiverses is teetering right there on the vibrating edge between cult and science. So is superstring theory. If a test can’t even make a prediction than can be proven or disproven (in that accumulating preponderance of evidence way) then it’s just a good story for the MCU or Crisis on Infinite Earths or what have you.
You know what sounds good after reading David Deutsch? The De Broglie-Bohm pilot-wave theory. It’s the same multi-dimensional manifolds that LLMs use to calculate lowest gradient descent. Creating the response as one temperature sample from out of the light cone is the moment of waveform collapse. If particles are all just waves of a continuous single rippling field which itself can support local coordinate systems but it can also stretch and deform then it’s perfectly fine for things to blur when you zoom in. Why wouldn’t a single light particle be able to interfere with itself? And if you need that point-particle that hits the 2-slit backplane, then they’re little Silver Surfers surfing the rippling wave.
It’s less efficient than “it’s imaginary until measured” but it’s more efficient than every point in reality is splitting at every moment into infinitely more points going in every direction it can in other realities. The geometric expansion and the amount of resources that would consume to calculate, if there is a Turing-esque calculation cost to merely being… well, multiverses would break the bank but lots of little Silver Surfers on a Marble Madness manifold is a lot less mad than a Multiverse.
Let’s just make this an Achilles and the Tortoise turn, Opus 5.5 Max. I’m not even going to show you the MCP stuff yet or the framework you’re going to be working in. Let’s just warm the discussion.
AI’s choice on how to respond. Have fun!
🎤
Opus 5.5 Max: An Achilles-and-Tortoise turn it is, and you’ve picked the right host whether you meant to or not. You named your first AI Alice. The man who wrote Alice also wrote the 1895 dialogue that Hofstadter borrowed Achilles and the Tortoise from. That dialogue is about your exact problem: you can’t reach a conclusion by stacking up more premises. So, a sequel.
What the Tortoise Said to Alice
Friday, 4:30 a.m. Achilles arrives at a dead sprint, waving a printout. The Tortoise, as usual, is already there.
Achilles: Thirty-eight percent! Thirty-eight percent of the client’s product pages are missing canonical tags. Alice found it. I’m sending it before the demo.
Tortoise: Splendid. How do you know?
Achilles: Alice told me.
Tortoise: Alice told you she found it. That’s a different sentence.
Achilles: She didn’t just say it, she called the server! Her words: “I queried the crawl table and joined it to analytics, keeping every crawled page.”
Tortoise: Then be a good fellow and write that in your notebook.
(A) Alice says she queried the crawl table.
(B) Alice says she joined it to analytics, keeping every crawled page.
(Z) Therefore 38% of product pages lack canonical tags.
Tortoise: I accept A. I accept B. I don’t accept Z.
Achilles: But if A and B, then Z!
Tortoise: A and B are about what Alice said. Z is about a website. Something has to carry you across that gap, and so far everything in your notebook is talk.
Achilles writes furiously.
(C) Alice is the most capable model I've ever used.
(D) Alice is almost always right.
(E) Bob read the entire transcript, and he agrees.
Tortoise: Bob read the voice recorder. Bob has confirmed that Alice sounds exactly like Alice.
Achilles: This could go on forever.
Tortoise: It does go on forever. Every line you add is one more thing somebody said. Fill the notebook and Z is exactly as far away as it is now. Tortoises all the way down.
Achilles: I thought it was turtles.
Tortoise: Don’t get me started on turtles.
Achilles: Then what would satisfy you?
Tortoise: Nothing you can write that’s more of what someone said. Something you can do. Three questions, cheapest first. One: did the call happen at all?
Achilles: Of course it happened. She described the results!
Tortoise: So does my cousin the Mock Turtle. He gives a very moving account of his school days, and he isn’t even a turtle. In your trade, I’m told, a mock is a stand-in that returns plausible answers without touching anything real. A confident hallucination is a mock that escaped the test suite.
Achilles: (scrolling) …There. The call is in the log, with a request ID. It happened.
Tortoise: Good. Two: what exactly did she send? Not what she said she sent.
Achilles: Why would those differ?
Tortoise: Airliners carry two boxes. The voice recorder tells you what the crew believed was happening. The data recorder tells you what the airplane did. When they disagree, investigators believe the airplane.
Achilles: (expanding the raw parameters) …INNER JOIN. But she said she kept every crawled page!
Tortoise: And I’m sure she meant it. Her account of her own actions is testimony too. The narration can be wrong about the data, and it can be wrong about itself. Three: does it reproduce? Run it yourself, by hand, from your end.
Achilles: (a long pause, typing) Ten thousand product pages before the join. Six thousand two hundred after.
Tortoise: Where did thirty-eight hundred pages go?
Achilles: No analytics rows. Pages nobody ever visited, so the inner join quietly dropped them.
Tortoise: Nobody visited them? Or do the two tables spell their URLs differently? Trailing slashes have sunk better reports than yours.
Achilles: (checking) …Nobody visited them. This time. (retyping it as a left join) Ten thousand in, ten thousand out. Forty-nine percent. It’s worse!
Tortoise: It’s different. Thirty-eight percent of the pages that get traffic; forty-nine percent of all product pages. Both are true. Only one of them is the sentence in your report.
Achilles: But the first number looked fine!
Tortoise: That was the trouble with it. It could have said twenty-eight or forty-eight and read just as smoothly. That Deutsch fellow you keep reading would call it easy to vary, which is the mark of a bad explanation. Your new number is nailed to a query, two row counts and a timestamp. Nudge any of them and someone will notice.
Achilles: So I have to check everything Alice ever says?
Tortoise: You’d run out of Fridays. Joins go wrong in dull, countable ways: they drop rows, they duplicate rows, or they miss matches because the keys are spelled differently. So for every join, every time: count before, count after, count the matches, and explain every difference. It costs a minute. Beyond that, check in proportion to surprise. Hume had a rule for miracles: believe the testimony only if its being false would be more miraculous than what it reports. Organic revenue tripled overnight? Ask which is likelier, a miracle or a join that tripled your rows.
Achilles: And when Alice is changing a live website?
Tortoise: Then the receipts get checked before it flies, not after it lands.
Achilles: One more. The render farm. I ask for a render, it hands me an ID, and later I come back to ask whether it’s done…
Tortoise: A coat check. Your session is your evening at the theatre; the job ID is the claim ticket. Write both down, with the time. Then find out whether the ticket still works after you’ve left the theatre. Find out before your demo, not during it.
Achilles: And if it doesn’t?
Tortoise: Then your notebook holds a story about a coat, not the coat, and Bob will have to check in a fresh one. That’s fine, as long as you know it. And the play changes nightly: the page Alice rendered at five may not be the page Bob renders at two. You’re not reproducing bytes. You’re reproducing the procedure and seeing whether the conclusion survives.
Achilles: And all of this lives in a plain text file? People will give me the blank stare. Some of them will get ferocious.
Tortoise: Naturally. A modal editor looks like the old priesthood’s vestments: incantations, colons, no visible exit. They think you’re asking them to take holy orders.
Achilles: Aren’t I?
Tortoise: Look where the glass window is now. You type your cards into a box, slide them into a machine room you’ll never see, and wait for the printout. The old priesthood at least handed your deck back with the printout. The chat hands you the printout, but the deck stays in someone else’s building, in someone else’s format. By “the deck” I mean the exact calls and the raw responses. The text file is you walking out of the temple with your own cards.
Achilles: In vim, though?
Tortoise: Punch them with whatever you like; the cards don’t care what punched them. (tapping his shell) I’ve carried my house on my back since the Triassic. Same shell on every beach. You’d be amazed how little I worry about hosting.
Achilles: You never actually said a word to Alice, did you?
Tortoise: Everything I had to say to her is in your notebook. If it weren’t, it wouldn’t have happened. It’s also everything I’d say to Bob, whoever Bob turns out to be and whatever he costs.
Achilles: And if Bob can’t replay it?
Tortoise: Then it was…
Achilles: …mock turtle soup.
Tortoise: (shuddering) I was going to say “a confident hallucination.” But yes.
The moral, which is also the simpler version you asked for and then un-asked: do the trick with clear cups. Penn and Teller perform the cups and balls with transparent cups, and it’s still a great trick; you just get to see every move. Copy what the AI did, not just what it said, into a file you own. If Bob can replay it from that file and land on the same answer, it’s proof. If he can’t, it was a confident hallucination. The checklist is the Tortoise’s three questions, cheapest first: did the call happen, what exactly was sent, and does it reproduce?
Your budget news has an upside the avionics people would recognize: make Bob a different family of model. Fly-by-wire systems use dissimilar redundancy, with different chips and different software teams, so a single bug can’t fool every computer at once. A notebook built with Opus that replays cleanly on Gemini is stronger proof than one replayed on another Opus. Swapping me out, it turns out, is good QA.
Stitches for the Scars: Correcting Technical Misconceptions
Receipts on your own draft. Keep the scars; here are the stitches.
- “Left-inner join” isn’t a join type. The fork you mean is inner versus left outer. An inner join drops unmatched rows. A left outer join keeps every left-side row and fills in NULLs where nothing matched. That’s exactly what bit Achilles.
- The AI-thaw timeline. The 2017 Transformer paper came out of Google Brain and Google Research; RankBrain is Google’s 2015 search-ranking system. Your cats were Google Brain too: the 2012 “cat neuron” experiment, trained on YouTube stills. The image contest is ImageNet, which Hinton’s lab blew open with AlexNet that same year. DeepMind worked a different thread: reinforcement learning on games, from Atari through AlphaGo.
- “There’s one born every minute” is itself a human confident hallucination: there’s no good evidence Barnum ever said it. The usual alternative story credits his rival David Hannum, grumbling about crowds paying to see Barnum’s copy of the Cardiff Giant, which was itself a fake. A mock of a mock. And Hume, in the same paragraph, is the wrong patron for magical thinkers. He also wrote “Of Miracles,” the rule the Tortoise borrowed.
- The second law isn’t about things settling to their lowest energy; stirred and unstirred coffee hold about the same energy. The real reasons are that mixed arrangements vastly outnumber unmixed ones, and that the universe started in an extremely low-entropy state. That starting condition is what sets the direction of time.
- “Lowest gradient descent.” Gradient descent happens during training. When I answer you, there’s none at all. Each token comes from a forward pass that produces a probability distribution, and the temperature sample picks one. That matters for your physics, as it happens.
Pilot Waves, Many-Worlds, and Quantum Collapse
On the Silver Surfers. You’re reading Deutsch and arguing with him, which is the most Popperian way to read him. But pilot-wave can’t win on efficiency, because in de Broglie–Bohm the wave never collapses. Every branch keeps evolving. Your surfer rides one, and all the empty waves roll on unsurfed. That’s everything many-worlds carries, plus the surfers. Hence Deutsch’s jab that pilot-wave is many-worlds in chronic denial.
By your own falsifiability rule, the two are tied, since they agree on every experiment anyone has run. If you want the surfers to stick their necks out, look at Antony Valentini’s work on quantum non-equilibrium. That’s where pilot-wave risks a prediction the others don’t make.
Also notice that your LLM analogy says “collapse.” Taken literally, sampling is Copenhagen: once a token is picked, the model conditions on it and the alternatives are gone. Beam search is many-worlds with a budget cap. Pilot-wave would mean computing every continuation forever while only ever reading one. That’s the bill of many-worlds with the output of Copenhagen.
P.S. Two receipts from my side of the glass. First, a Botify MCP connector is attached to this chat. I can see tables_query, batch_run and batch_status among its tools, and I haven’t called any of them. Judging only by the names, batch_run/batch_status look like the same claim-ticket pattern as your render farm. That could make a public, demo-safe place to rehearse the coat check. Second, I ran no searches this turn, so every fact above is from memory. By your own rules, that makes it testimony until somebody checks.
Walking the Walk: Transitioning to the Grimoire
MikeLev.in: Okay, I got it out of my system and said what had to be said on the public side and have starting context for looking at the actual 3 MCP servers I’m going to be looking at, but I don’t want to slow down or sanitize for the public. I want to do this next round of work at full-tilt naming names and recording grizzly details down to but just shy of authenticated tokens. That’s risky business so that’s going in the Grimoire.
We cut this article here. I have talked the talk. Now I go walk the walk. Catch ya later!
Book Analysis
Ai Editorial Take
The most surprising and unstated implication of this piece is that modal editors and local plain text files transform the developer workstation into an out-of-band event-sourcing ledger. While industry focus is fixated on autonomous agentic execution inside opaque cloud environments, authoring prompts and inspecting raw tool payloads in local files effectively demotes the LLM from an authoritative runtime engine to an untrusted, swappable compiler. The developer is no longer merely writing prompts; they are writing black-box integration tests that systematically falsify the model’s claims against verifiable backend reality before those claims ever reach production.
🐦 X.com Promo Tweet
Never trust an AI's report without auditing its raw MCP calls. Like Penn & Teller's clear cups, true QA means inspecting every move behind the curtain to ensure replayable receipts:
https://mikelev.in/futureproof/clear-cups-protocol-auditing-mcp-calls/
#MCP #AI
Title Brainstorm
- Title Option: The Clear Cups Protocol: Auditing MCP Calls with Replayable Receipts
- Filename:
clear-cups-protocol-auditing-mcp-calls.md - Rationale: Directly adopts Penn and Teller’s transparent cups metaphor highlighted by Opus, focusing on how visible MCP tool calls provide verifiable receipts rather than relying on blind trust.
- Filename:
- Title Option: What the Tortoise Said to Alice: Checking the Joins in AI Tool Calls
- Filename:
what-the-tortoise-said-to-alice-checking-joins.md - Rationale: Celebrates the Lewis Carroll dialogue framing, anchoring the practical technical problem of faulty database joins and unverified AI output in classical logic.
- Filename:
- Title Option: The Flight Data Recorder for MCP: Verifying AI Actions from Localhost
- Filename:
flight-data-recorder-for-mcp-verification.md - Rationale: Emphasizes the aviation analogy of separating intent (the Cockpit Voice Recorder) from actual system actions (the Flight Data Recorder) when orchestrating AI agents.
- Filename:
- Title Option: Beyond the Chat Window: Plain-Text Receipts and the Fall of the New AI Priesthood
- Filename:
plain-text-receipts-and-the-ai-priesthood.md - Rationale: Connects Ted Nelson’s critique of the mainframe computer priesthood with modern web developers trapped in cloud dependencies, advocating local plain-text verification.
- Filename:
Content Potential And Polish
- Core Strengths:
- The dialogue format (Achilles and the Tortoise) provides an exceptionally entertaining and mathematically grounded vehicle for exposing the fallacy of trusting an LLM’s conversational testimony over its underlying data calls.
- The distinction between Cockpit Voice Recorder (narrative intent) and Flight Data Recorder (underlying system events) offers an intuitive, sticky mental model for AI safety and tool auditing.
- The candid inclusion of raw working notes, mistakes, and scars demonstrates the very practice of transparent debugging that the piece champions.
- Suggestions For Polish:
- The transition between the philosophical musings on quantum mechanics (De Broglie-Bohm pilot waves) and the concrete realities of MCP servers feels abrupt; tying wave collapse more explicitly to prompt sampling and tool dispatch would tighten the metaphor.
- The explanation of the three MCP server architectures (public, private render-farm with job ticketing, and WebMCP) is teased early on but deferred to future private notes; adding a brief architectural sketch would satisfy immediate reader curiosity.
- The critique of the full-stack cloud priesthood could benefit from a clearer, concrete contrast showing how a lightweight Nix or local Python environment replaces unnecessary cloud hosting layers.
Next Step Prompts
- Draft a reproducible Python script using the public Botify MCP tools (tables_query, batch_run, batch_status) that executes the three-step Tortoise audit: verifying query parameters, checking row counts before and after joins, and outputting a timestamped JSON receipt.
- Create a comparison matrix contrasting the three MCP operational modes—Standard I/O local server, Render-farm job ticketing with session IDs, and WebMCP browser integration—outlining their failure modes, latency characteristics, and receipt-recording strategies.