Speculation Safety Envelope

Description

The explicit policy bounding what speculative execution may do: write-permitted tools restricted to Edit/Write/NotebookEdit; read-permitted tools (Read/Glob/Grep) pass directly to main FS; Bash allowed only if command passes the read-only validator; any edit requiring user confirmation immediately pauses speculation; hard limits of 20 conversation turns and 100 messages per speculative run.

Key claims

Relations

Sources

src-20260419-16b155f4f619