5779c762de
The primary bridge builds a `replace`-mode `EditTool` because `PiEditExecArgs` carries `old_text`/`new_text` pairs that no other mode accepts. The advisor roster passed its own instances straight through, and those follow the session's configured `edit.mode` - `hashline` by default, whose schema is a single `input` string - so every native advisor edit failed validation instead of touching the file. Both bridge-only tools now come from `cursor-bridge-tools.ts`: `createBridgeEditTool` builds the wrapped `replace` instance, and `bridgeToolMap` substitutes it into a granted map. The substitution is gated on `edit` actually having been granted, since the tool is constructed rather than looked up - handing one to a read-only roster is the #5680 escalation. The advisor's own loop keeps its instance; only the exec map is swapped. (cherry picked from commit e6cf9f8046c595cab9793b4b2a5795d8488d8d22)