citar/engine/ holds the rules and does no I/O — it turns a state and an action into a new state
or an error. Everything else calls it: the browser client over HTTP, a scripted bot in-process, a
language model through an adapter, an external agent over MCP. Every action any of them can take is
registered once in citar/engine/tools.py, which is why the interfaces cannot drift apart and why
a model has exactly the powers a human has. Around that sit the measurement parts — metrics,
benchmarks, probes, a usage ledger and costed reports — because the point is not only to play the
game but to know what happened.