> - Path-sandboxed file ops. Keeps agents locked to a working directory
How is it supposed to work, if agent can simply run "cat" command instead of using skill for file read/write/etc?