Added a readonly tool allowlist enforcement for workflow steps, blocking execution of state-mutating tools (`fn_task_update`, `fn_task_move`, etc.) during workflow step runs. The policy is wired into the executor and merger execution paths, with tests covering allowlist enforcement and a documentati Fusion-Task-Id: FN-4366
380 B
380 B
@runfusion/fusion
| @runfusion/fusion |
|---|
| patch |
Enforce workflow_steps.toolMode="readonly" as a hard tool allowlist at the engine's agent-session layer. Readonly workflow steps can no longer hold Edit, Write, Bash, or task/agent mutation tools. Steps that attempted to write under toolMode="readonly" now fail closed with a READONLY_VIOLATION outcome instead of silently staging files.