xal v0.1.0

Model: gpt-5.6-sol

Working directory: ~/Projects/xal

> /safety

## Nothing runs without your say

A permission engine sits between the agent and your machine — `allow` / `ask` / `deny` per tool. When a rule says ask, it stops.

**Tool:** `bash rm -rf node_modules`

denied (error)

**Tool:** `read .env`

blocked (error)

**Tool:** `edit src/index.ts`

plan mode (error)

In *plan mode* it can only read. It investigates, writes the plan, and hands the decision back to you:

## Plan review

Review the implementation plan above. What should Xal do?

- **Approve and build:** Restore the previous writable mode, or normal mode, and begin implementing.
- **Clear context and build:** Start a new session that carries only this plan. Context: 45% used.
- **Request changes:** Keep plan mode active so the proposal can be revised.

- *custom modes* — ship your own `docs-only` or `ci` mode; `yolo` exists for when you mean it
- *secret redaction* — keys scrubbed from what the model sees, what is stored, and what is on screen
- *undo* — `/undo` rewinds the conversation *and* the files; worktree isolation when you want distance
- *workspace trust* — an untrusted folder cannot load project config or plugins
