Good point. “Read-only” only protects against mutation; it doesn’t limit what data the MCP client can actually see.
The important distinction is whether MCP requests inherit the same per-user filters and role restrictions as an authenticated web session, or whether the MCP credential represents a broader fixed identity. If it’s the latter, then the blast radius is much larger than the wording suggests.
I’ll clarify that distinction in the MCP/security section, because container visibility and authorization scope matter more here than simply calling the tools read-only.