I think that there is AllowSyscall list inside seccomp.go of guardian as a default. I just wanted to provide this AllowSyscall list as an option each time when I push an app. That's too bad to hear that you have currently no plan to change the configurable option on it.