cli: use pledge(2) to restrict syscalls where available Signed-off-by: Ariadne Conill <ariadne@ariadne.space>