The approval policy is declared on the tool, once
TrueForge resolves its @read-only / @write /
@destructive approval selectors from MCP tool annotations. The
classification lives next to the implementation, and both front ends inherit it
automatically.
| Tool | Annotation | Approval |
|---|---|---|
scan_dependencies, lookup_advisories, assess_blast_radius, summarise_triage, propose_patch |
readOnlyHint |
no |
open_pull_request, merge_pull_request |
destructiveHint |
yes |
A read-only tool cannot mutate a remote. Anything touching GitHub state is destructive by construction, so a mis-tagged tool fails closed.