Cargo permissions to detect tampered dependecies

My proposal leveraged unsafe (in conjunction with Cargo features) not as a "permission", but the fundamental modeling dimension around which all other permissions are based.