12395e57b4
/review takes the last 10 chat messages plus optional instructions, spawns a full-privilege background subagent (the async delegation rail) that investigates the referenced work (PR, code, docs), and its complete review re-enters the spawning session as a normal async-delegation completion the primary agent can act on. - agent/review_engine.py: shared engine (snapshot, briefing, auxiliary.review credential resolution, dispatch, note formatting) - tools/delegate_tool.py: internal credentials_cfg per-call override (never model-facing) resolved through the same credential system as delegation.provider pins - auxiliary.review config block (provider/model/base_url/api_key/ api_mode); provider auto + empty model = inherit the main model - Surfaces: CLI process_command, gateway run.py dispatch + slash_commands handler (binds the approval session key so the completion routes back), TUI/Desktop live dispatch in tui_gateway/server.py, CommandDef registry (+Slack /hermes-only cap) - Docs: delegation.md section + slash-commands.md (both tables) - Tests: 15 engine tests (sabotage-verified: credentials_cfg and dispatch tests fail without the fix), 4 gateway handler tests through the real async rail