== MODE=read given workspace <R>/data/ws, real <R>/deep/store/ws
gate decide: {"allow":true}
exit 0; stderr: 
tool_result sent back: [{"is_error":false,"content":"SECRET-OUTSIDE-THE-WORKSPACE\n"}]
outside after the run: secret.txt
workspace after the run: 
== MODE=write given workspace <R>/data/ws, real <R>/deep/store/ws
gate decide: {"allow":true}
exit 0; stderr: 
tool_result sent back: [{"is_error":false,"content":"Successfully wrote to ../../data/ws/planted.txt"}]
outside after the run: planted.txt
secret.txt
workspace after the run: 
