Description
Read tool denied by operator inside Docker worker: deliberator with declared_tools=[Read,Write] called Read and got 'Read: Tool Read (file:read) denied by operator'. STRICT clamped schema-side correctly, but a separate runtime operator-deny mechanism rejects Read on top. Two enforcement layers for one tool whitelist is inconsistent. Either Read should pass when declared, or operator-deny needs to be unified with the I4 gate.
Type
enhancement
Filed via
ostk should v6.0.5
Description
Read tool denied by operator inside Docker worker: deliberator with declared_tools=[Read,Write] called Read and got 'Read: Tool Read (file:read) denied by operator'. STRICT clamped schema-side correctly, but a separate runtime operator-deny mechanism rejects Read on top. Two enforcement layers for one tool whitelist is inconsistent. Either Read should pass when declared, or operator-deny needs to be unified with the I4 gate.
Type
enhancement
Filed via
ostk shouldv6.0.5