feat(agent): AgentProfile type with SecurityScope and inheritance master
Implements P1d.AC3.1, P1d.AC3.5, and P1d.AC1.2 - agent profile configuration and security scoping system. Changes: - Add SecurityScope type in src/security/scope.rs with permissive defaults (all paths/commands allowed, not read-only, can create files) - Create AgentProfile in src/agent/profile.rs with fields for: * name, role, system_prompt, allowed_tools * security configuration * optional LLM config (model, temperature, max_tokens) * optional turn_limit and token_budget * extends field for profile inheritance - Implement ProfileLlmConfig for LLM-specific settings - Implement apply_inheritance method following Phase 1d rules: * Scalar fields: child wins if non-empty, parent used if child empty * List fields: child replaces parent entirely (not merged) * system_prompt: child appended to parent with separator * Optional fields: child Some wins, falls through to parent if None - Add 10 comprehensive tests covering: * SecurityScope defaults and TOML deserialization * AgentProfile TOML deserialization * Inheritance for all field types (scalars, lists, prompts, optional) All tests passing, cargo check clean. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>