01 / 05
Agents hold raw credentials
Developers embed real card numbers and API keys in agent context. A single prompt injection or context leak exposes the actual account — with no per-agent cap and no way to revoke just one agent.