# verify_docx_diff

[MAINTENANCE] W1-K — compare a registered docx derivative's recorded source hash against the CALLER-supplied CURRENT hash of the source document's on-disk bytes (compute it locally, e.g. sha256, immediately before calling this) and report whether the derivative is stale — i.e. whether the source has changed since this derivative was generated. Optionally also pass current_derivative_content_hash to detect the derivative itself having drifted out of band. Never errors on a 'stale' verdict — that is a normal, expected result, not a failure. Persists the verdict onto the derivative row (last_verified_at / last_verify_is_stale / last_verify_reason) as an audit trail; never changes the derivative's status itself. Returns {derivative_id, is_stale, source_changed, derivative_changed, reason, derivative}. Persistent-state disclosure: on hosted Meridian, supplied text and project/session metadata -- including task log entries, pinned decisions, sprint items, notes, handoff/goal state, and HITL queue items -- are sent to and stored in Meridian's service, in an isolated per-tenant Postgres database (Neon); self-hosted deployments keep the same categories in the configured local SQLite/Postgres database. This data is visible in the dashboard and API, and may resurface in later project context or handoffs. Notes and pinned decisions can be deleted individually; task log entries and sprint items can be deleted via the dashboard/API (not exposed as an agent-facing tool); HITL queue items and handoff state have no per-record delete. Full removal of any of this data is available via project or account deletion, using the documented controls. Do not include secrets.

Agent View of the PolicyLayer registry record for `verify_docx_diff`. HTML page: https://policylayer.com/tools/io-github-ajc3xc-meridian/verify-docx-diff

## Facts

- Tool: `verify_docx_diff`
- Server: Meridian (`@meridianmcp/mcp`) — https://policylayer.com/tools/io-github-ajc3xc-meridian.md
- Install: `npx -y @meridianmcp/mcp`
- Homepage: https://github.com/meridianmcp/Meridian
- Risk category: Read (Low risk)
- Registry record: grade D, identity unverified
- Server auth posture: gated
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 5 (2 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `project_id` | string | no |  |
| `project_name` | string | no | Project name — an alternative to project_id; resolved to the id internally. project_id wins if both are given. |
| `derivative_id` | string | yes |  |
| `current_source_content_hash` | string | yes | Caller-computed content hash of source_path's CURRENT on-disk bytes, computed fresh right before this call. Required. |
| `current_derivative_content_hash` | string | no | Optional caller-computed content hash of derivative_path's CURRENT on-disk bytes. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "verify_docx_diff",
    "arguments": {
      "derivative_id": "<derivative_id>",
      "current_source_content_hash": "<current_source_content_hash>"
    }
  }
}
```

## Why verify_docx_diff is rated Low

Even though verify_docx_diff only reads data, uncontrolled read access leaks sensitive information and racks up API costs: an agent caught in a retry loop can make thousands of calls a minute without anyone noticing.

## Use case

AI agents call verify_docx_diff to retrieve information from Meridian without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Meridian:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "verify_docx_diff": {}
  }
}
```

## Other tools on Meridian (234)

- `accept_handoff` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/accept-handoff.md
- `acquire_docx_document_lease` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/acquire-docx-document-lease.md
- `answer_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/answer-hitl.md
- `batch_mutate` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/batch-mutate.md
- `capture_research_finding` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/capture-research-finding.md
- `checkpoint` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/checkpoint.md
- `claim_docx_region` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-docx-region.md
- `claim_file` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-file.md
- `claim_sprint_item` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/claim-sprint-item.md
- `clear_capability_profile` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clear-capability-profile.md
- `clone_profile_layer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/clone-profile-layer.md
- `delete_custom_hook` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-custom-hook.md
- `delete_note` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-note.md
- `delete_sprint_item_pointer` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-sprint-item-pointer.md
- `delete_watchlist_query` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/delete-watchlist-query.md
- `dismiss_hitl` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/dismiss-hitl.md
- `fan_out_sprint_items` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/fan-out-sprint-items.md
- `idle_until_all_done` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/idle-until-all-done.md
- `index_equation` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-equation.md
- `index_figure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-figure.md
- `index_table` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/index-table.md
- `ingest_document` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document.md
- `ingest_document_structure` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/ingest-document-structure.md
- `link_figure_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-figure-caption.md
- `link_flag_to_section` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-flag-to-section.md
- `link_proposal_lineage` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-proposal-lineage.md
- `link_table_caption` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/link-table-caption.md
- `log_task` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/log-task.md
- `purge_ai_log` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/purge-ai-log.md
- `receive_messages` — Destructive — https://policylayer.com/tools/io-github-ajc3xc-meridian/receive-messages.md
- …and 204 more: https://policylayer.com/tools/io-github-ajc3xc-meridian.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-ajc3xc-meridian · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-ajc3xc-meridian
