pub fn is_dangerous_shell_command(command: &str) -> bool
Hard-deny shell patterns under non-FullAccess modes (escape / wipe / remote pipe).