The controller should grant each agent run only its task's tools and credentials. If agents execute code, put that execution in a sandbox with scoped network and filesystem access. A prompt role or MCP tool description does not enforce these permissions.

Moved to https://andy.smith.wiki/3mwnojmcmit3t/