The trust-boundary analysis is strong. One implementation detail I would add is that a signed JSON log on the same host is still operator-controlled. I would hash-chain each tool request and response, include server identity, policy decision, and result digest, then anchor periodic chain tips to an independent transparency log or second system. That helps distinguish a malicious tool from a compromised client. For MCP deployments, do you prefer an external anchor per run or a batched anchor with a published interval?