Part of #603.
Acceptance
Extend the existing request-scoped tool compatibility and directed-message modules for current caller declarations, flat custom exec and child subsets. Expose only actually declared handlers; preserve exact custom input, typed Item identity, Call identity, stream order, tool results and same-child followup. Prevent opaque assignments in both official/subscription directions. Recover only an authoritative exact assignment with matching author/recipient/call provenance; never execute JavaScript in Gateway, infer plaintext from ciphertext or substitute a placeholder. Opaque-only tasks require caller-owned restatement/reissue using original requirements and child state/results without replaying effects. Reuse current codecs. Deterministic adversarial lifecycle/history tests and bounded current-Codex Code Mode/V2 evidence; retained malformed envelopes and zero-width exact-output failures remain failures.
Dependencies
None.
Verification
Risk class: strict. Follow docs/agents/verification-policy.md and docs/specs/cli-subscription-providers.md. Historical feasibility does not qualify the production candidate.
Part of #603.
Acceptance
Extend the existing request-scoped tool compatibility and directed-message modules for current caller declarations, flat custom exec and child subsets. Expose only actually declared handlers; preserve exact custom input, typed Item identity, Call identity, stream order, tool results and same-child followup. Prevent opaque assignments in both official/subscription directions. Recover only an authoritative exact assignment with matching author/recipient/call provenance; never execute JavaScript in Gateway, infer plaintext from ciphertext or substitute a placeholder. Opaque-only tasks require caller-owned restatement/reissue using original requirements and child state/results without replaying effects. Reuse current codecs. Deterministic adversarial lifecycle/history tests and bounded current-Codex Code Mode/V2 evidence; retained malformed envelopes and zero-width exact-output failures remain failures.
Dependencies
None.
Verification
Risk class: strict. Follow docs/agents/verification-policy.md and docs/specs/cli-subscription-providers.md. Historical feasibility does not qualify the production candidate.