LLM Cognition Rust MIT active

mpl

Contracts, quality measurement, and audit trails for AI agent communication — between MCP, A2A, and your application.

Overview

mpl, the Meaning Protocol Layer, addresses a gap that opens once agents call tools and each other in production. MCP and A2A specify how the messages move. Neither specifies what a correct message contains, how good the exchange was, or how anyone proves later what was sent. In a research prototype that is fine. In a regulated system it is the whole problem.

The layer sits between an agent and its transport, whether that is MCP, A2A or plain HTTP, and does three things to every interaction. It validates the payload against a versioned semantic-type contract, so a field that was supposed to be a currency amount cannot quietly become a string. It scores the exchange against a quality profile — quality of meaning, or QoM — producing a number that can be trended rather than a pass or fail. And it writes a BLAKE3-hashed, provenance-attributed audit record, so the sequence of calls is reconstructable afterwards by someone who was not there.

The audit property is the reason this is written in Rust rather than in the language most agent code is written in. An audit trail that can be rewritten is not an audit trail, and a hash chain is only as trustworthy as the process that computes it. Determinism and memory safety are requirements of the claim, not stylistic preferences.

The framing that matters is that mpl is additive. It does not replace MCP or A2A and has no interest in becoming another transport. Teams reach for it when an auditor, a regulator or an incident review asks a question their logs cannot answer, and the obligations they are usually working against — SOX, GDPR, HIPAA, the EU AI Act — are about demonstrability rather than about capability.

Where it loses: for a single agent calling two tools this is overhead with no return, and a guardrail library will cover the realistic failure modes more cheaply. The contract-authoring burden is also real. Semantic types have to be written by someone who understands the domain, and a contract that is wrong is worse than no contract because it is trusted.

The comparison people reach for first is with agent guardrail libraries, and it is worth separating the two. A guardrail inspects content and blocks what it dislikes at the moment of the call, which is a runtime safety concern. mpl asks a different question: was this exchange well-typed, how good was it, and can anyone demonstrate that afterwards. A system can want both, and neither substitutes for the other.

The quality-of-meaning score is the most experimental part and the part we are least confident about. Reducing the fidelity of an exchange to a number invites the usual pathology of any metric under pressure, and a quality profile that is easy to satisfy will be satisfied rather than met. We currently treat QoM as a trend to watch rather than as a threshold to enforce, and whether that discipline survives contact with an organisation that wants a pass or fail is an open question.

Primary use case

Compliance and audit substrate for production agentic systems — contracts, quality metrics, and tamper-proof audit trails for MCP and A2A traffic.

How it compares

mpl is one option in a category that includes MCP (Model Context Protocol), A2A (Agent-to-Agent) , and agent guardrails. Our Compare page has the full side-by-side.