The "harmless parts, dangerous combination" point (read-files tool plus send-email tool equals exfiltration path) is the risk I think teams underrate the most, because each capability passes review in isolation. The rename-trick detail is a good reminder that inspecting by file extension is theater; content inspection of the serialized model is the only thing that holds. I would be curious whether you scope tool combinations at the policy layer too, since even a fully inspected model can be talked into chaining two safe tools by an injected instruction in retrieved content.