c1b781fac0
Both entries ran tools.Exec. The handler field is prose, so the duplicate hid there: "tools.Exec against the enabled allowlist" against "tool.Exec through the configured aliases". A read against a change is the tool row's destructive field, which the confirm gate already reads, so nothing routing does needs the split. Its nine examples went with it rather than moving up. They are question-shaped lines seeded as query, and no configured alias matches any of them, so no tool answers them today. Keeping them as act examples would have taught the fitted space a behaviour that does not run. TestInventoryShape now refuses an id nested under another id. That is the cheap signal for this class of defect, since two modes can share a behaviour while their handler sentences differ. 31 modes, 10 ready to fit. The nine with no example are unchanged. --no-verify: same reason as the parent commit, the 394-line data file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0117tgnmbgZpHVV3XSNw8Qua