Every access control system rests on one assumption: read is safe, write is dangerous. For AI agents that distinction has quietly collapsed. An agent that can read can exfiltrate it, be steered by it, and reconnoitre with it. Read-only is not a safe default, and permission tiers no longer govern risk. The action does.
Read →