Replace the generic global "Command approval" modal for sandbox-denial
escalations with a clean, inline approve/deny card in the chat feed (all
workspaces). Enrich the approval contract end to end with sandbox `detail` +
`category` (filesystem/network) so clients can frame the decision as "re-run
with full access?" instead of a raw risk code. Ordinary (requires_manual_review)
approvals still use the modal; humanize its risk-code copy.
Also prove and document that agents can read global skills/plugins under
~/.cowork (skills dir, ~/.cowork/plugins, discovered plugin skill paths) inside
the OS sandbox (read-only) and via the file tools, including scoped children;
clarify that .agents/ is the marketplace source layout, not a runtime namespace.
Co-authored-by: Cursor <cursoragent@cursor.com>