Your agent can DROP TABLE, read /etc/passwd, and drain a wallet. By default, nothing stops it.
AI agents are incredible. They write code, query databases, call APIs, manage infrastructure, and now — thanks to protocols like x402 and AP2 — they can spend money autonomously. But here's the gap n