8376f56ab4
Adds native sandbox execution runtime, dynamic review middleware, and workspace file handling, with supporting stream events, prompt, and scope registry changes plus architecture docs.
EvoScientist Native Sandbox Runtime
This directory pins the native Web command sandbox dependency. It is a deployment dependency, not an npm application and not a CLI execution backend.
Install exactly what is recorded in the lockfile during environment preparation:
npm ci --omit=dev --prefix runtime/native-sandbox
Web full startup then performs a real fail-closed isolation preflight. It never downloads dependencies and never falls back to Docker or the host shell.
Platform tools:
- macOS: Node 20.11+,
bash,rg,python3,pandoc, and/usr/bin/sandbox-exec - Linux: Node 20.11+,
bash,rg,python3,pandoc,bwrap, andsocat
Run the host-specific black-box suite after installation:
EVOSCIENTIST_RUN_NATIVE_SANDBOX_TESTS=1 uv run pytest -q tests/test_native_sandbox_integration.py