28e517fc1b619dcebee9d702a1789af60de3e7c5
Task 9.3: OutboundService now delegates the execute step to CapabilityBroker (policy-gated + obligation-enforced) instead of calling a provider directly, while keeping idempotency + rate-limit + the command/attempt ledger. BLOCKED obligations → command BLOCKED; a fail-closed throw marks the command FAILED then propagates. AdaptersModule imports CapabilityModule; P4/P6/P8 egress now flows through the broker unchanged. Updated 6 spec constructions; added a DENY_OUTBOUND test. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
No description provided
Languages
TypeScript
88.8%
JavaScript
10.4%
Dockerfile
0.4%
HTML
0.3%
Shell
0.1%