buildTool Fail-Closed Defaults

Description

Safety-by-default pattern in the Claude Code tool factory: new tools register with isConcurrencySafe: false and isReadOnly: false by default. Tools must be explicitly marked safe — they are not assumed safe until proven otherwise. Paralleled by AutoBE's 5-gate compiler chain.

Key claims

Relations

Sources

src-20260419-16b155f4f619