The harness runs the tool call for the LLM. It is trivial to not run the tool call without approval, and many existing tools do this.