What defaults are safest when a coding agent can run shell commands from user prompts?