returns a plan, and the parent process executes it on the real GPU. This is how the MCP task service evaluates untrusted code safely. Run: kbox iterate examples/dev ...