The Shell tool schema lacked a `required_permissions` parameter,
preventing models from requesting elevated sandbox permissions
(e.g. unrestricted network access). This adds:
- `required_permissions` parameter to the Shell tool schema in tools.json
- Sandboxing instructions in the Shell tool description so models know
when and how to request permissions
- `shell_sandbox_policy()` in request.rs to map the parameter to the
protobuf `SandboxPolicy.requested_sandbox_policy` field
Co-authored-by: Cursor <cursoragent@cursor.com>