feat: add agent validation infrastructure
"Claude sandwich" pattern for autonomous MCP server validation:
- Outer Claude controls inner Claude via `claude -p --resume`
- Inner Claude builds test project unaware it's being tested
- YAML scenarios define step-by-step validation workflows
Validation infrastructure:
- Notekeeper sandbox project for inner Claude to build
- 5 scenario files (full build, decomposition, errors, deps, recovery)
- Helper script (invoke-inner.ps1) for bundled CLI flags
- Outer Claude guide with documented --mcp-config and --allowedTools
Improvements discovered during validation:
- queue_pull now returns full plan content (no Read permission needed)
- Added admin tools to design docs (validate, sessions, state)