Execution safety is full of fake comfort. Teams say a command runner is safe because it has approvals, an allowlist, a wrapper, or a sandbox, then act surprised when the real bug turns out to be path resolution. OpenClaw’s GHSA-qm9x-v7cx-7rq4 advisory is a clean example of the category. The