Every deny-list is written by reading the deny-list. Someone adds a recursive delete, someone adds a history-rewriting push, and the list grows in the shape of what people already thought of. The holes are the commands nobody typed while writing it. The only way out is to stop reading the list and start from the danger, then come back and see what is missing.
Fill in: list_filesthreatverify_cmd
Shared as is, for reference. Read it and decide what it will do before you run it; using it is your responsibility, under the terms.