a97c287aee
The primary could delegate to a worker but not create or reap one over MCP — spawning was a raw REST POST /workers. BridgeMcp now adapts WorkerService so a worker's whole lifecycle runs through MCP: bridge_spawn returns the new worker's sessionId (for bridge_send) and paneId (for bridge_stop); bridge_list projects the tracked workers; bridge_stop tears one down. The subscription boundary stays enforced inside WorkerService (bridge_spawn surfaces a guard breach as a tool error without touching herdr). Tools are thin static adapters, unit-tested by parity.