"Hallucinated success is the worst failure mode of agentic systems" matches what we see too, and the on-chain receipt is a clean answer for the signing domain. The part I would push on is retries. You fixed confirm-before-send for the human side, but what happens when the connection drops mid-call and the harness retries the send tool? An e-signature request is exactly the kind of side effect that wants an idempotency key per document and counterparty, so a retry cannot produce two live signing requests in the counterparty's inbox. Also, the 60% to 94% pick-correctness jump from halving the tool surface is a number more MCP server authors should hear; verbose-but-specific beating short-but-ambiguous is exactly how tool retrieval behaves in practice.