Blocks dangerous operations: rm -rf, sensitive file access, privilege escalation, and more are denied before execution.
Gates risky commands behind human approval (optional): configurable commands require explicit operator sign-off via a web GUI before the agent can proceed.
Simulates blast radius: wildcard operations like rm \*.tmp are evaluated against real files before running, and blocked if th