I'm running a little experiment right now with leaving a proxy comment without up-voting with my own bot instance, going to look what it comments on for a day to see if that is a viable use-case.
If this option doesn't turn out, I'm contemplating either what you proposed, or a whitelist or blacklist added to the current experiment.
A nice whitelist option I like to use is whoever the bot account is following. You can have your bot pull following every so often and make a list from that. This will allow you to easily update your whitelist with the click of a button through your favorite front end.