Four measurements decide the shape, all taken today: 1. --allowedTools is not an enforcement boundary. ListAgents and ScheduleWakeup ran on microvm missions whose list is Read Edit Write Bash Agent. The flag governs prompting, not availability, so any task-permission layer must be enforced by our own gate. 2. The guest already has every tool's output on disk (the tap appends the whole payload, tool_response included), so taint is computable guest-locally with no network call and no added latency. 3. The taint store would already be protected — the hook-files rule refuses reads and writes to /root/toolhooks from both Bash and the write tools. 4. Provenance is a CONTAINER-tier control. A microVM reaches only the provider and the forge through a name-matched CONNECT allow-list; a container reaches any public host. Saying it matters equally on both would be padding. Task permission: a per-phase "agent_tools" key (NOT "tools", which security_scan already owns), defaulted from what phase kinds actually used, enforced by the gate. Provenance: taint hostnames out of fetched responses, deny an outbound call WITH A BODY whose target is one of them — the asymmetry being that reading a host a page mentioned is research and sending data to it is the attack. String taint is rejected outright as a false-positive generator, which is this module's cardinal sin. Both ship in shadow (gate.would_deny) first, because today's corpus is 171 tool calls and 15 curl invocations and cannot validate a rule. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WZb5A2kfVfjpdwSochkuHz