CLI user intent: "trade perp" User LLM (local) plans call sequence Call Batch sequence of CLI calls Execute Sequence CLI LLM, one call at a time Mobile Notification user reviews batch, approves in principle ✦ Temp Approval Object SHIELD deterministic policy known · malicious · unknown Server LLM adjudicates unknowns vs. approval object MFA Prompt hard gate real-time confirm LATENCY SKILLS REGISTRY 2FA ALWAYS TRIGGERED SLOW ON 2FA unknown malicious → hard MFA diverges ✓ known-good → silent pass ✓ within approval → pass