A prompt is not a permission model
While building the plugin layer of our own platform we had to answer a question most agent stacks defer: what is this thing actually allowed to call, and where is that enforced? The answer could not live in a prompt.