Follow-up from the review of #26 (merged). Verified on the merged head by driving cmd/cudly-mcp over real stdio:
- The README 'Audit log' section says every purchase attempt is appended. Attempts refused before the provider call (operator gate off, missing credential scope, dry_run/confirm validation errors) write no record. Either reword it to 'each preview and each attempt that reaches the provider', or also audit refusals, which is arguably more useful for an audit trail.
- The server.go NewServer comment says a server with an unusable audit log 'should not accept purchase calls at all'. Only startup is gated; a write failure during a call warns on stderr and leaves the result unchanged (as the README documents). Reword the comment.
Follow-up from the review of #26 (merged). Verified on the merged head by driving cmd/cudly-mcp over real stdio: