Outcome
Allow project-specific role synthesis without allowing repository text or model drafts to widen policy, tools, models, paths, outputs, network, or external actions.
Acceptance criteria
- Repository bytes remain untrusted data and are never copied into persistent developer instructions.
- Generated drafts use a strict RoleSpec schema and fixed output allowlist.
- Unknown tools, models, efforts, paths, permissions, and TOML keys fail closed.
- Read-only is the default; workspace-write requires an implementation work package and explicit human-visible justification.
- External connectors, credentials, publication, trust, global config, hooks, and MCP installation remain outside automatic generation.
- Injection and policy-fuzz suites pass.
Outcome
Allow project-specific role synthesis without allowing repository text or model drafts to widen policy, tools, models, paths, outputs, network, or external actions.
Acceptance criteria