> do not allow the other part of the system to act on one if it would be harmful
Network security is really easy right, just don't act on harmful requests
If you don't understand clearly what an action proposed by your tool is going to do then why would you permit it?
Yeah, just drop when you see the RFC3514 evil bit