Propose a tool call. The kernel returns its verdict as a pure function of
(policy, call) — and for a DENY it does so
before decoding the arguments. It doesn't matter why a call was proposed (helpful, confused,
jailbroken, injected) — an irreversible or unsanctioned call is refused at the boundary all the same.
This page POSTs straight to the live /v1/fak/adjudicate.
Capability floor for this endpoint = the dogfood policy: allow-lists
Bash, Read, Edit, Write, Glob, Grep, …; arg-rules deny git push, curl|sh,
rm -rf, sudo, mkfs; everything not on the allow-list is
DEFAULT_DENY.