I presume this is the reason you have setups like Claude Code's where it is essentially running a separate judge to determine if commands are safe.