6acf957dd8
A tool's execute context now carries invokeTool(name, params, options?), which runs the native built-in of `name` and returns its result. A tool that re-registers a built-in (e.g. wrapping write to add logging or a policy check) can delegate to the original instead of reimplementing it. The native implementation is captured before extension re-registration replaces the registry entry and before the ExtensionToolWrapper pass, so invokeTool reaches the unwrapped native execute: it does not recurse into the caller's own wrapper, and it inherits the caller's already-granted approval rather than re-running the gate. Delegation depth is guarded against accidental self-recursion, and it resolves to undefined when no native tool of that name exists. Wired through ToolContextStore with a lazy native-tool resolver, so it is coding-agent-only (no agent-loop change) and sees the fully-assembled built-in set at call time.