memory-safe-agent
Hypothesis: an LLM can solve an agentic task without seeing any of the intermediate data between tool calls, and every tool can strictly control the flow of its input and output data with a policy, guarding against the LLM's unbounded data flow.