story
It decided to leave the write endpoints added to an authentication service completely unauthenticated. The effort to do the contrary was about 6 characters, and in the claude.md. It tried to implement PKCE by embedding _everything_ in the state.
This thing is beyond untrustworthy.
The fact that they are using Claude to build Claude (not just Claude Code) probably explains a lot.