SCC plugin host: discovery, loading, permissions, execution, diagnostics.
Process plugins (spec section 15): a scc-plugin.toml manifest plus a
command speaking JSON over stdio. One request per process spawn (simple,
crash-isolated, no lingering children); timeout_ms + failure_policy
bound every call. Grants are checked before spawn — a plugin never
executes code it was not granted (spec 21).