Imagine an AI coding agent asked to fix a production bug. It has authenticated correctly, received access to the repository and been given the tools it needs. Reading the relevant code is reasonable. Running tests is reasonable. But those same credentials may also let the agent inspect unrelated files, call an external service or perform […]