Tool-arsenal validation and risk gating for offensive engagements: risk-tier classification of tools (safe/active/intrusive/credential/dangerous), approval gates where intrusive tools are inert until approved (approve-once-then-free or pre-authorized allowlists), fail-safe denial for unattended runs, loud audited warnings for the hottest actions, egress scope enforcement, and pre-engagement availability checks. Use when preparing a toolset before an engagement, deciding which tools need operator approval, building approval gates into security tooling, or validating that an arsenal is present and scoped before a run. Derived from the T3MP3ST platform's arsenal approval sys…