The controller should grant each agent run only its task's tools and credentials. If agents execute code, put that execution in a sandbox with scoped network and filesystem access. A prompt role or MCP tool description does not enforce these permissions.