Guard package-manager installs, dependency changes, CI, and agent-run commands before suspicious project code executes.