1cb3ab6173
A goal quality gate is a shell command persisted by `/goal gate add` and later executed with `subprocess.run(shell=True)` at every goal turn boundary (run_gate), with no approval prompt. On the messaging gateway, slash access is backward-compatible: with no `allow_admin_from` list configured (the default), every *allowed* chat user is treated as unrestricted. So an allowed but non-admin remote sender could add an arbitrary shell command and get authenticated RCE as the Hermes process account. Gate ONLY the shell-creating operation (`gate add`) behind the existing fail-closed explicit-admin check (`_resume_caller_is_admin`, the same one that guards cross-origin `/resume`). `gate list` / `remove` / `clear` stay open so a non-admin can still inspect and recover. CLI/TUI/Desktop `gate add` is local (the user already has host access) and is unchanged. Salvaged from #91677 by @unsupportedpastels — narrowed to the single shell-creating op and reusing the existing admin helper rather than renaming it. Contributor's regression tests preserved. Co-authored-by: unsupportedpastels <theoldwizard123@pm.me>