Implements the first pragmatic slice of issue #3627 / #410:
- add agent-facing tool with list/check/request/delete/inject
actions
- reuse existing secure CLI secret capture path via getpass-backed callback
so secret values never enter model context
- support as an alias for the existing
skill frontmatter
- redact execute_code stdout/stderr before returning tool output
- expand redaction patterns for Twilio SIDs and JWTs
- register the new tool in discovery/core toolsets and add regression tests
Gateway DM+delete secret capture remains scoped as follow-up work per the
Phase 1 issue discussion.