FYI: I added a "policy-rcd-declarative-deny-all" package that contains an alternative default policy denying all service startup requests. As soon as it passes my tests, I'll upload that to unstable.
You might want to update the script then to install policy-rcd-declarative-deny-all (which depends on policy-rcd-declarative) and drop the manual policy config file. If wanted, I could also upload this to backports? Regards, -- To the thief who stole my anti-depressants: I hope you're happy -- seen somewhere on the Internet on a photo of a billboard