MCP is a good boundary for the tools themselves, but the write path was hard. Agents stayed well behaved on reads and then raced each other writing the same file, because nothing in the capability layer knew two edits were meant to be one change. Guarding the tool call is not the same as guarding the transaction.
Vlad Zoff
The read-only vs trusted mutation profiles make sense. I especially like making workspace authority explicit instead of assuming cwd is the project. The other thing I'd make explicit is which writes are reversible and which aren't; a file edit and a deploy or delete call shouldn't live in the same risk bucket just because both are "write" operations.