⚠️ READ-ONLY MODE: You are not permitted to modify the workspace. Use this tool only for inspection: reading files, listing directories, running builds/checks, git status/log/diff, searching, etc. Writing to the OS temp directory is allowed — use a literal path under `$TMPDIR` (the daemon temp root) or /tmp, or bind a scratch directory with `NAME=$(mktemp -d -p "$TMPDIR")` and reference `$NAME` (the `-p` variant honors the target directory — a bare `mktemp -d` on macOS ignores TMPDIR and lands elsewhere, still inside the allowed temp roots).
The guard rejects before execution, in every spelling — do not try to work around it:
- Any write outside the temp directory: output redirects (`> file`), in-place editors (`sed -i`, `awk -i inplace`), `dd of=`, `tee`/`touch`/`cp`/`mv`/`rm` against workspace paths, and package managers (`npm`, `pip`, `brew`, ...). `tar` is list-only (`tar -tzf f`, `tar tzf f`, `tar --list`) — extraction/creation is rejected in every form, including into temp directories.
- git config/repository injection: global `-c`, `--config-*`, `--exec-path`, `--git-dir`, `--work-tree`, and `GIT_*` environment variables (`GIT_PAGER` excepted — a pager never spawns on captured output). `git -C <path> <read-only subcommand>` is allowed.
- Unprovable command words: a variable can stand for the command name only when it is bound to a plain literal earlier in the same invocation (`BIN=cargo; "$BIN" --list` passes). Substitution-derived bindings (`BIN=$(which cargo)`), transitive chains (`X=rm; Y="$X"`), and unbound variables are rejected — write the command name literally instead.
Blocked commands stay blocked in every form — do not attempt to re-invoke them via built binaries, relocated copies, or alternate spellings. If you absolutely require this action to do your job - note it in your final response instead of attempting it further.