Missing the configuration block for managed rule group configs and the default inspection level should be COMMON. Without this, the rule set can be added to an existing WAF to enable bot control but configuration is incomplete