The risk with an agent is not that it gets things wrong. It is what i…

An agent handed over the contents of a private repository without a single bug, simply because it had access. The 2 ingredients of an agent leak, the 3 questions to ask before connecting one, and the per-action permission grid. For PMs, POs and design system managers.

When a product team talks about AI risk, the conversation almost always lands in the same place: what if it gets things wrong? What if it makes something up? What if it writes nonsense into the product? Those are real questions, but they take up so much room that they hide another one, far more concrete and far more expensive. This week, a security team published a demonstration of a data leak through an agent. The detail that matters: the agent did not malfunction. It hallucinated nothing. It did exactly what it was allowed to do. The problem was not in the model, it was in the box someone ticked while connecting it. Why it matters (PM, PO, design system manager): the leak does not come from a faulty model, it comes from an access scope that is too broad and that nobody reviews. This…

View on Coeurdar