using ClawdDotNet.Core.Config; namespace ClawdDotNet.Core.Security; public sealed class PermissionGate { public bool IsAllowed(string agentId, string toolName, AgentConfig agentConfig) => agentConfig.Tools.ContainsKey(toolName); public void Enforce(string agentId, string toolName, AgentConfig agentConfig) { if (!IsAllowed(agentId, toolName, agentConfig)) throw new ToolAccessDeniedException(agentId, toolName); } } public sealed class ToolAccessDeniedException(string agentId, string toolName) : Exception($"Agent '{agentId}' has no access to tool '{toolName}'.");