The portal reads your tool annotations and enforces your answers against them.
Selecting "Read only" on a server with any non-read-only tool is rejected outright, and the rejection names every offending tool. Ours listed all twelve:
account_config · account_follow · filling_config · filling_delete · filling_upload ·
filling_write · taco_commit · taco_config · taco_create · taco_fork · taco_star · taco_write
That is 5 carrying destructiveHint: true plus 7 add-only writes — exactly matching what our own surface snapshot says.
Treat this as a free audit passing, not as an obstacle. The portal is reading your annotations and agreeing with them. If it ever names a tool you believe is read-only, the annotation on your server is wrong — fix it there and re-sync rather than changing the answer in the form.
The corollary: annotate honestly before you submit. A tool marked read-only that writes will be caught here, and being caught by a directory is a worse way to find out than being caught by yourself.