I've been on a look out for any harness that properly secures a protocol to the LLM, but they're all just "here's some tools, hopefully you don't use bash for everything".
And they all do. I had to add special instructions to tell Claude Code to prefer its built-in read_file tool, rather than using `sed -n 180,210p` everywhere.