Imagine you hired a talented but clumsy sous chef. They can plate beautifully, but they keep elbowing the wine glasses. You could retrain them — months of coaching — or you could just put bumper rails around the stemware. This paper is the bumper rails. The core claim: you can wrap a pretrained vision-language-action (VLA) robot policy in a lightweight geometric safety filter that guards not just the fingertips but the entire forearm, wrist, and gripper — the parts that actually cause most collisions — without retraining the policy at all. The filter models the arm links as five ellipsoids and the hazard as a keep-out ellipsoid reconstructed from a single RGB-D frame at reset. A control barrier function (CBF) program then constrains every commanded joint velocity to keep all five ellipsoids outside the hazard zone. Sparse optical flow tracks the hazard as it moves, updating the keep-out zone without running expensive detection again. The ladder here is not against another safety filter — there isn't a clean prior-art baseline for multi-link VLA shielding with moving hazards. Instead, the comparison is against the unshielded VLA policy itself (π₀.₅ from Physical Intelligence). Unshielded, the arm collides 65.62% of the time across six simulated hazard-motion conditions. The shield drops that to 27.27%. Safe-success — completing the task without any collision — jumps from 29.35% to 50.43%. On physical hardware (SO-101 arm, four tasks), collisions fell from 11/16 to 3/16 episodes. These are honest numbers: the shield doesn't eliminate collisions, it roughly halves them, and the authors don't hide this. Architecturally, this is a CBF-based safety filter — a well-studied family in controls — married to a modern VLA policy stack. The key engineering insight is computational: the barrier program for five ellipsoids runs on the CPU in 2.2ms at p99, completely off the critical path of the GPU-bound VLA inference. Meanwhile, they trim the VLA's vision-language prefix and reduce flow-matching denoising steps to cut policy inference from 343ms to 177.3ms on an integrated GPU. The whole system shares heterogeneous edge hardware (Jetson-class), which is the real deployment constraint the paper respects. The integrity picture is mixed in ways worth naming. Simulation uses the authors' own setup in MuJoCo with Isaac Sim perception, and the six hazard-motion conditions (static, linear, oscillating, circular, random, approach) are reasonable but not a community benchmark. The physical experiments are small — 16 episodes per condition — which is typical for hardware papers but means confidence intervals are wide. Ablations are genuinely informative: removing multi-link coverage (gripper-only shielding) loses protection; freezing the hazard estimate at reset degrades performance that tracking recovers. Code and project page are published. The milestone that matters is closing the remaining ~27% collision rate. The filter is solving a convex program per timestep, so the geometry is fast but the safety guarantee depends on the quality of the hazard ellipsoid fit and the optical-flow tracking. Noisy depth, occlusion, and fast hazard motion are the failure modes. The next concrete number to watch: sub-10% collision rate on a standardized manipulation benchmark with dynamic obstacles, which would make this deployable in shared human-robot workspaces. The obvious experiment they didn't run: multiple simultaneous moving hazards, and hazards that are partially occluded. The paper's perception pipeline fits a single keep-out ellipsoid from one RGB-D frame at reset and tracks it via sparse optical flow. Scaling to cluttered scenes with several moving objects is the natural next step, and the honest read is (a) — they scoped to the single-hazard case to get clean ablations and a publishable result, and multi-hazard extension is likely the next paper.