Capability gates
External agent config
Coding jobs
MCP bridge
list_mcp_tools reads configured stdio server tools. call_mcp_tool requires action-specific approval and returns capped output.
MCP calls are local stdio processes from MCP_CONFIG_PATH. Treat each server’s side effects according to that server’s own behavior.
Safety model
- Bridges are disabled by default.
- Delegation is routed as
DELEGATED_AGENTrisk. - Mutating delegation requires approval.
- Output is redacted and capped.
- Working directories stay under sandbox policy.
- Realtime voice does not get agent delegation by default.