Custom Scripts run as root on a schedule, so the expensive mistake is not tangled logic — it is a simple script aimed one directory too high. The prompt now asks for the dry-run form and an explicit line on what gets destroyed, and a scan of the generated code blocks raises a banner regardless of whether the model bothered to warn. Scans fenced code only, so prose mentioning rm does not trip it.