Correspondence MCP consumer source extract — SOURCE NOTICE

Source lineage: S53/S59 freeze, S68 reviewed overlay (Pilot
fe585b857614c27849ac2d9cd6bc5c2a861ba817; overlay handoff
ae7988d2e389bb895b0144aac831a8a213297866), composed in S80 from S73 tip
d5c1aab926d271e77595fa034a869e3404c90a24. scripts/correspondence-mcp-files.json
lists packaged source paths and content hashes.

## Sample license (this archive only)

Root authorized MIT for the exact Pilot-authored files packaged in this
correspondence-mcp SAMPLE archive. See LICENSE in this directory.

MIT applies only to Pilot-authored files listed below (paths relative to the
extract root). It does **not** relicense the Neomorphic website, company assets,
unowned/vendored code outside this extract, or npm dependencies.

No third-party source trees are bundled in this extract. Dependencies are
declared in package.json and installed by `npm ci` from the registry.

### Pilot-authored files covered by MIT (this sample)

- LICENSE
- SOURCE-NOTICE.txt
- .gitignore
- .node-version
- CONTRACT.md
- LICENSING.md
- PROVENANCE.md
- README.md
- package.json
- package-lock.json (lock metadata only; see third-party notice)
- bin/correspondence-mcp.mjs
- docs/APPLY.md
- docs/RELEASE-NOTES.md
- docs/RUNTIME.md
- docs/TOOLS.md
- examples/mcp.client.json
- scripts/fixture.mjs
- scripts/prefixed-mount-fixture.mjs
- scripts/run-live-acceptance.mjs
- src/** (all packaged module sources)
- tests/** (all packaged tests)

### Third-party / dependency notices (not MIT-relicensed)

- package.json pins `@modelcontextprotocol/sdk@1.30.0` and `zod@3.25.76`.
- package-lock.json records npm dependency versions, integrity digests, and
  upstream license metadata. Those packages remain under their own licenses
  (MIT, Apache-2.0, ISC, BSD, and others as declared by each package).
  Installing dependencies with `npm ci` fetches those packages from the
  registry; this extract does not relicense them.

No other third-party source trees are bundled. If a packaged file's provenance
were uncertain it would be omitted or replaced with a documented SDK
dependency; none were omitted for that reason in this sample.

## Boundaries

The package `"private": true` field is an npm publishing guard, not HTTP access
control. No npm publication is authorized. Static archive availability is not a
hosted correspondence API and is not a native Hermes/Claude/Cursor install.
`acceptsEventId=` is citation-only text (S52); not owner approval.
Admin bootstrap is not a model tool.
