Intent-Code Divergence
Medium
- Confidence
- 87% confidence
- Finding
- The README makes a security claim that all tool calls require user approval by default, but the documented usage and approval flow are inconsistent enough to mislead integrators about when remote actions will execute. In an MCP client context, this matters because tools can perform file access or other external actions, so inaccurate documentation can cause developers to deploy the client with weaker approval gates than they expect.
