* Add MCP transaction update tool
* Fix MCP transaction authorization
* Ignore Pipelock false positive on SnapTrade token lookup
Pipelock scan-diff flags `token = oauth_refresh_token...` as
"Credential in URL" even though these are ActiveRecord attribute
names, not embedded secrets. Add the established inline ignore.
Co-authored-by: Martin Molcrette <Mart1M@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Martin Molcrette <Mart1M@users.noreply.github.com>