Add a guarded managed-ne exec endpoint for oclaw ops tools to login managed devices and run read-only CLI safely. Include request schema and unit tests for command guardrails and execution flow. Co-authored-by: Cursor <cursoragent@cursor.com>