Under --safe, PreToolUse denies any edit or command that resolves outside the
project root. It is a guard rail on the agent's own tool calls rather than an OS
sandbox, which is the right altitude for the threat it addresses: a model
wandering out of the repo, not a hostile one.