e7645cec49
Each `runSubprocess` call re-ran `loadCapability<Rule>()`, `loadSessionExtensions()`, and `discoverAndLoadCustomTools()` because `ExecutorOptions` and the `createAgentSession()` call inside the executor omitted three pass-through fields the parent had already paid for. The already-correct paths (skills, context files, workspace tree, MCP manager) showed the intended pattern. - Cache `rules`, `extensionsResult`, and `loadedCustomTools` on the parent's `ToolSession`. - Add `rules` / `preloadedExtensions` / `preloadedCustomTools` to `ExecutorOptions`; forward them from both `runSubprocess` call sites in `task/index.ts` and into the executor's `createAgentSession()`. - Add `preloadedCustomTools` to `CreateAgentSessionOptions` and skip `discoverAndLoadCustomTools()` when it is supplied. - Shallow-clone `extensionsResult.extensions` when reusing `preloadedExtensions`, so the per-session autoresearch + custom-tools inline wrappers never leak back into the caller's array. Fixes #2190