Strict but lenient:
Now you don't have to choose between "strict" and "agent-reviewed".
Most of the time, we will block any perilous command execution request from the agent.
But you can run a verified, checked command set through a command macro for when you need it.
(Sounds like a custom config, but it's completely different!)
My philosophy is to provide a safer but easier way to run complex commands.
MCP is too rigid; CLI is lenient, but too dangerous.
This is the best compromise.