Defines the exact role, tool permissions, and POSIX shell invariants. Eliminates out-of-bounds agent operations.
Forces explicit chain-of-thought in dedicated deliberation tags before any tool call execution or irreversible mutation.
Mathematically verifies execution success ($? == 0, HTTP 200, schema matching) before reporting task completion.
Enforces strict JSON-RPC / Markdown format constraints, preventing leaky free-text output in machine workflows.
Writes ephemeral state to L1 working files via shell heredocs, preserving context across restarts and model migration.