- Add CreateSessionOptionsDto with sandboxDir, systemPrompt, and allowedTools fields
- Add clampCwd() to shell-tools to prevent cwd escapes outside the sandbox
- agent.service.ts, git-tools.ts: already merged via #147 with full implementation
Closes#134
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>