What's wrong with this entry?
A comprehensive allowlist classifying hundreds of known MCP tool names as "search" or "read" operations, likely for auto-approving read-only MCP operations.
Infrastructure added, not yet visibly wired to auto-approval logic.
- Search tools: ~90 tools from Slack, GitHub, Datadog, Sentry, Google, Atlassian, Stripe, PubMed, Brave, and more
- Read tools: ~270 tools covering Slack reads, GitHub detail views, Grafana dashboards, PagerDuty, Jira/Confluence, Asana, MongoDB, Elasticsearch, Figma, Puppeteer screenshots, and more
- Classification uses snake_case normalization of tool names
MCP tool classification allowlist — PT4() at line ~327832 (search for "slack_search_public")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.