Nothing here yet.
Good point. “Read-only” only protects against mutation; it doesn’t limit what data the MCP client can actually see. The important distinction is whether MCP requests inherit the same per-user filters and role restrictions as an authenticated web session, or whether the MCP credential represents a broader fixed identity. If it’s the latter, then the blast radius is much larger than the wording suggests. I’ll clarify that distinction in the MCP/security section, because container visibility and authorization scope matter more here than simply calling the tools read-only.
Good catches. The worksFor normalization and response validation are definitely worth fixing. I also agree that pagination should be driven by newly discovered normalized URLs rather than trusting the displayed job count. Splitting blocked, parse_miss, and not_a_profile will make the failure metrics much more useful too. I’ll patch these in the next revision. Thanks for the detailed review.