.omo/evidence/omo-senpi-adapter/20260719-curated-agents/task-2.md
mode: "subagent", executionMode: "in-process", non-empty Senpi-adapted prompts, stripped legacy brand tags, and the exact nine-name allowlist required by the plan.call_omo_agent, background_output, Context7/web tools, todo tools, ast-grep helpers, clone/npm/history shell commands, and related sentinels.bash implementation accepts only a structured program: "curl" | "gh" plus an argument vector, invokes it with execFile rather than a shell, and positively allowlists read-only operations.curl --version, rejected curl --output ..., and left both forbidden files absent.The definition still exposes the plan's literal bash tool name, but curated children receive a shell-free implementation whose schema and command planner cannot express a general shell command.
No claim is made that Senpi's ordinary builtin bash is read-only; it is replaced only for the five curated in-process agents.