An OpenShell policy needs explicit enforcement settings: inspected endpoints default to audit, and filesystem rules default to best_effort. For strict boundaries, select enforce and hard_requirement, then verify the effective policy and actual denial behavior.
Valid policy syntax does not imply the intended enforcement
The schema defaults an inspected endpoint's enforcement to audit: violations are logged but requests continue. enforce makes those rules blocking. Landlock best_effort can continue without the requested filesystem rules when they cannot be applied; hard_requirement fails startup instead. The mandatory baseline remains a separate requirement.
Source: policy schema defaults.
These settings should be explicit in a strict pilot, followed by tests that an authorized request succeeds and a forbidden one is denied. Check the actual applied paths, not just successful YAML parsing. No such deployment test was performed here.
The earlier MCP limitation still matters: allowing a tool name does not constrain every possible argument or prove the resulting action appropriate.