Cherry-pick of upstream Shannon PR #329. Adds per-mode output format
builders in queue-schemas.ts so the notes field description steers LLM
output toward defensive context when exploit is disabled. Updates
agent-execution to pass the exploit flag through to getOutputFormat.
Co-Authored-By: Paperclip <noreply@paperclip.ing>