AutoModeMiddleware can be bypassed when an inner middleware replaces the tool call before execution
AutoModeMiddleware evaluates the original ToolCallRequest, but an inner middleware (e.g., HumanInTheLoopMiddleware) can replace it with a protected tool call before execution, leading to policy bypass. Ordering [auto_mode, hitl] is vulnerable while [hitl, auto_mode] blocks correctly.
