SIGN IN SIGN UP

fix(mcp): advertise readOnlyHint on every read-only tool

tools/list shipped no `annotations` at all, so every client that gates on
readOnlyHint treats codedb's navigation tools as potentially side-effecting.

In Claude Code's plan mode this is not just a prompt: the permission
evaluator's MCP gate rewrites the decision to "ask" before the allow-rule
lookup runs, so a configured `mcp__codedb__*` allow rule is never consulted
and "don't ask again" has no persistence path. The gate's only escape is
`annotations.readOnlyHint`. Net effect today: every codedb_search /
codedb_symbol / codedb_read call prompts while planning.

Annotate the 19 tools that only read the index. codedb_index rebuilds the
on-disk index and codedb_bundle can dispatch it, so both stay unannotated.
The profile builders (core/slim/mini) and the augmented bundle list all
derive from this same static JSON, so the hint rides along on each —
verified over a live stdio handshake on the default mini profile.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TqTyTJVJ4cd1MzFF54Hrbh
D
Daniel Poelzleithner committed
03d72fe6606854702f0643e301146f38dcd2d56d
Parent: dcbe2f6