Sandbox-first command safety layer for MCP-compatible coding agents, protecting commands executed through its safe_exec tool by blocking destructive operations and requiring human approval for ambiguous commands.