Plan-and-verify demo — the LLM emits a JSON workflow, Atmosphere's verifier chain runs over the plan AST, and only verified plans dispatch. Try the malicious goal: the verifier refuses it before any tool fires.
Try one of these:
Run plan-and-verify