Architecture: Keep the implementation thin. The Python wrapper is the only execution entrypoint for agents and only adds command allowlists, write/delete gates, HOME redirection, timeout handling, ...