I think the fact you need tool calling to stop it doing that, shows the underlying issue with trusting it to do anything without a human