Block a user
End-to-end validation of researcher agent
Implement context compaction for subagent
Implement researcher agent loop (tool use cycle)
Define researcher agent system prompt and context structure
Integration tests for Tool Broker end-to-end
Unit tests for each enforcement layer
Implement ValidateCall gRPC endpoint (dry-run)
Implement ExecuteTool gRPC endpoint
Implement tool result tagging
Implement prompt injection firewall
Implement credential injection
Implement loop and thrash detection
Implement tool discovery (DiscoverTools RPC)
Implement tool execution dispatch
Enforcement layer 5: Network egress check
Enforcement layer 4: Path allowlist check
Enforcement layer 3: Lineage constraint enforcement
Enforcement layer 2: Agent type manifest check
Enforcement layer 1: Session override check
Implement Agent Type Manifest loader