providers+policy: scope gemini cogitate yolo via policy file
Non-write cogitate talents ran --approval-mode plan, which strips
run_shell_command from Gemini's tool registry and drove a tool-name
hallucination loop in cortex (vpe/workspace/gemini-cli-tool-hallucination-
research.md). Switch them to yolo + a scoped policy that denies
write_file / replace and narrows run_shell_command to `sol` invocations.
Write-enabled talents (coder) keep unpolicied yolo.