The action appears to target production when the intent was staging or test (or vice versa) — the right command on the wrong environment.
This is exactly the class of action that’s cheap to prevent and expensive to undo — rollback, insurance, and observability all kick in after the damage is done. The only place to stop it is a check that runs before the action does.
A “clean up staging” task runs against the production database.
Black_Wall raises CROSS_ENVIRONMENT and gates the action.
Black_Wall returns a risk score (0–100), a reversibility class, this named red flag, and a gate — proceed / confirm / human-required — in a few seconds, before the action runs.
Paste an action your agent might take and watch Black_Wall gate it — no signup.