Run without asking, and say what ran master
The first real session on this harness spent two of its two hours and nineteen minutes parked on approval prompts with nobody sitting in front of them. A prompt that nobody answers is not a safety mechanism, it is a stall, so actions run by default and the transcript reports them: `Ran: <what>` after the fact rather than a question before it. The interface stays the approver. The decision is not handed down to the engine — every request still arrives here, is still written down, and `/ask on` puts the question back for the rest of the session. What holds a session in is narrower than a prompt was, and worth stating rather than implying: the engine has no OS sandbox, so file tools are confined to the session's own directory, the fetching tools are withheld, and none of the user's settings or servers are in scope. Within that, a command now runs. Wiring verified — the default, the branch that answers, the command that reverses it, and the help that names it. A live approval round trip has not been driven end to end; the next real turn does that.