This library is an orchestration core, not a sandbox.
- Registered step functions are trusted Python and have the host process's authority.
- Prompt text and returned payload values may contain private data; compact evidence intentionally omits them, but callers still own payload storage.
- The intake writer validates filename components, bounds writes to the resolved queue directory, refuses overwrite, and uses atomic replacement.
- There is no network or provider adapter in the public package.
- There is no code installer or subprocess runner in the public package.
Do not add dynamic imports, arbitrary file paths, generated-code execution, or a live provider without a separate threat model and tests.