Per-primitive
{ enabled, defaults?, requiresApproval? }. requiresApproval gates the primitive’s sensitive agent actions behind a human approval (true forces it, false opts out of the built-in default).{ mode, toolkits?, tools?, custom_auth_configs?, requiresApproval?, approvalToolkits? }. mode is open | allowlist | blocklist. requiresApproval gates connecting any toolkit; approvalToolkits gates only specific slugs.