The tool only accepted set_mode/add, so entries added via MCP could never be removed. Now passes the full action set through to the same endpoint the UI uses and returns the resulting mode/entries. Verified on device: add -> delete round trip leaves the filter empty.