Deciding what the agent may touch
The useful agent is the one holding credentials, which is also the dangerous one. Every tool needs its own scope, rate limit and blast radius, and the permission list has to be positive: enumerate what is allowed rather than attempting to name every way a request could be abused.

