pub fn load_tool_security_policy( workspace_root: &Path, config_path: &Path, ) -> Result<ToolSecurityPolicy>