As a temporary solution for limitations of one of the environments in which RRG is supposed to be deployed, we agreed to re-introduce a mechanism where a list of allowed commands is built into the agent. This is not supposed to be generally enabled except builds for this specific environment and available only until the technical limitation for using real signed commands there is gone. To emphasize the temporary nature of this workaround, we are going to implement it in a rather hacky way that does not require changing any existing code, is purely additive and thus trivial to delete.