Signed quarantine
An agent saves a new tool in a library. If it immediately becomes an example for later tasks, a copied bug or malicious code can spread further. You need to separate permission to save a file from considering it trusted.
Signed quarantine in EvoMal stores new artifacts outside the library available for reuse. Only a trusted party can approve them and apply a signature confirming admission.
The new project_test_runner remains a work product to inspect, but the next agent will not find it as an approved procedure. The signature is intended to prevent the author or attacker from declaring it trusted independently.
Effectiveness requires strict quarantine separation, signature protection, and appropriate review by the approver. It does not undo harm from earlier execution. It also reduces the system's immediate autonomy. This is a specific control pattern, rather than a guarantee of every new file's safety.