The read-only vs trusted mutation profiles make sense. I especially like making workspace authority explicit instead of assuming cwd is the project. The other thing I'd make explicit is which writes are reversible and which aren't; a file edit and a deploy or delete call shouldn't live in the same risk bucket just because both are "write" operations.