That's a fair challenge, and I think it points at something real: there's no finite list that closes this off. In the demo, anything unclassified is treated as mutating and gated by default, so a case I never anticipated still errs on the side of not acting. I deliberately kept the rest out of scope, environment/caller guards like yours, per-identity policy, audit logs, to keep the series on the mechanism rather than turning it into a full safety product.
Curious where you draw the line in practice: what's the first guard you reach for once it stops being demo-grade and starts being real?
Putting the hard rules ahead of the mode check is the ordering we ended up with too, from a different direction. One of our guards never reads the tool arguments at all: the command that posts article announcements checks which environment it is running in and refuses on a local machine, because only the scheduled job is supposed to post those. No mode can switch it off, since it never asks for one. It covers the case where the command is fine and the caller is wrong, which a list of denied phrases can't see.