* improve(agents): stop prompt-side refusals for requested work
Drop the system prompt Safety section, the blanket credential ban, the external-content IGNORE list, and template ask-first/when-in-doubt rules. Runtime tool policy, sandboxing, and exec approvals already gate risk; the prompt now says requested actions with available tools are authorized.
* improve(agents): drop refusal prose from tools, skills, and SOUL template
Soften screen/app-UI and subagent-output notes, drop confirm-before and --yolo avoidance lines from skills, and let SOUL.md stop saying 'when in doubt, ask'. Bootstrap completion recognizes the previously shipped AGENTS.md/SOUL.md bytes so the template edit does not end a pending onboarding.
* test(agents): drop prompt wording pins
Delete tests that only asserted literal prompt/tool-description phrases; keep one discriminating assertion per input-dependent branch, cache/ordering invariants, boundary markers, and the refusal-trigger guard.
* fix(agents): keep legacy credential prompt result and align docs
Legacy string and unknown-availability callers of buildCredentialSafetyPrompt keep the documented handoff-only result; the credential-use line needs known control-tool availability. Update system-prompt and SDK migration docs for the Care section, and keep xurl auth checks on auth status.
* fix(agents): align remaining care guidance with requested work
Resolve contradictory workspace-template wording for requested representation and sharing, correct the bootstrap step count, and describe sandbox host access in terms of available tools and permissions.
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
* fix(agents): acknowledge supplied credentials after requested work
Complete requested credential use or storage, then give a brief factual acknowledgment without repeating the value. Preserve the action-oriented execution guidance and restore focused Workshop ownership and scoped cron lookup regression checks.
Validation: 372 targeted tests passed remotely; formatting, diff checks, and uncommitted autoreview passed.
* test(agents): align prompt snapshots and verify fetch spill recovery
Regenerate the Codex prompt fixtures for the current credential acknowledgment and cron guidance. Preserve the 800-character web-fetch budget while checking complete spill recovery and a single matching sanitized boundary pair.
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
* fix(agents): preserve source content in bounded fetch previews
---------
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>