The Execution Pipeline · PreToolUse
Seven phases decide the fate of every tool call.
Each call enters at Phase 0 and descends through gates and scoring engines. The pipeline short-circuits the moment any phase emits a score that crosses the active level's deny threshold (strict 0.5, balanced 0.8, permissive 0.9); otherwise the final score is a weighted average across every engine that ran.
score → safe
suspicious
critical
PreToolUse
packet
$ —
at phase 0
0.00
scoring
idle — press ▶ replay
awaiting evaluation
no scenario running
idle