It seems pretty obvious that the solution is auto mode (running a classifier on each action) + sandboxing