Content-aware provenance layer for Claude Agent SDK. Detects dangerous content at every tool I/O boundary, propagates classification across sub-agent dispatch, and enforces fail-closed policy.