Under --safe, PreToolUse denies any edit or command that resolves outside the project root. It is a guard rail on the agent's own tool calls rather than an OS sandbox, which is the right altitude for the threat it addresses: a model wandering out of the repo, not a hostile one.