Please report vulnerabilities privately through GitHub's security advisory form. Do not include credentials, private prompts, user data, or production logs in an issue.
An agent can act with the combined authority of every configured tool. Review tools before enabling them, apply least privilege, and require explicit approval for destructive, financial, or externally visible actions.