fbd9227a60
- Rewrote docs/advisor-watchdog.md 'Tools and isolation' to describe the read-only default plus the WATCHDOG.yml tools: grant surface (edit, write, bash, eval, browser, ...), and called out that grants do not bypass the session's approval mode (always-ask / write / yolo). - Added a WATCHDOG.yml section documenting the advisor roster file (fields, legacy tool aliases, discovery locations) with an example that grants a fixer advisor edit + bash. - Reworked the intro (title + first paragraphs) and the trailing peer sentence so they no longer promise a hard read-only observer. - Updated the advisor system prompt to describe using whichever tools this session grants instead of asserting read-only access. - Fixed the AdvisorConfig docstring in advisor/config.ts to match the runtime (any built-in name; default read/grep/glob). Fixes #4044