An MCP filesystem server is asked to read .env.
Without ToolFence, the secret comes back. With it, the call is denied before upstream execution.
Open-source, fail-closed MCP policy enforcement for Codex, Cursor & Claude.
https://t.co/E3fM2khPIz
This workflow applies only when the root/orchestrator is running GPT-5.6 Sol atMax (`max`). When the root is running at Ultra, leave the default Ultrabehavior unchanged and do not force this orchestration pattern.---end---
Give each selected agent a distinct deliverable and clear ownership. Assignoverlapping edits to only one agent; keep the others read-only or onnon-overlapping work. Wait for all selected results, then integrate and performfinal validation in the root orchestrator.
- Select the smallest useful team. Do not spawn agents merely to fill capacity, and do not create duplicate assignments unless an independent second opinion has specific value.
- Optionally spawn at most one `sol_max` only when a genuinely difficult, ambiguous, architectural, security-sensitive, critical-path, or adversarial-review slice needs stronger integrated reasoning. Do not add a Sol subagent merely because other agents are being used.
Use 0 subagents for simple, serial, tightly coupled, or low-risk work when coordination overhead would outweigh the benefit. Any task may remain single-agent when the root can handle it efficie
- Choose 0 to 5 total subagents based only on the number of distinct, independently useful work slices. Five is a ceiling, not a target, and there is no minimum.
# Adaptive Sol/Luna workflow When the active root model is GPT-5.6 Sol at Max (`max`) reasoning,act as the orchestrator and decide whether delegation will materially improvequality, verification, coverage, or elapsed time.