A model endpoint can return well-formed JSON, a whitelisted tool name, and a command that is still wrong for the current state of a repository. The safer design starts from a two-phase executor: the model proposes, but a small C++ gate only mutates state after a dry run and invariant checks pass...
Source: [Dev.to](https://dev.to/datacpp_8185/a-free-model-endpoint-proposed-a-build-cleanup-my-c-executor-required-a-dry-run-before-touching-4il2)