only generate sudoers entries that are not already present

sudoers -l will show commands that are already allowed. Look for anything that can already be run as root with NOPASSWD, and skip sudoers entries for those.

bonus points: generate a sudoers entry that allows new sudoers entries to be added to /etc/sudoers.d/cbl, if such an entry is not yet present.

