Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Part of the threat model. If that is an issue then don't add the capability to the agent. It is simple as that. But we cannot guarantee that the agent wont leak some information. So if you connect personal accounts (i.e. oauth) this information can be guarded with technical controls that sit outside of the agent. If the agent is authenticated with shared credentials then you have to add instructions and other soft guardrails but ultimately you should assume that everyone has access to the information.
 help



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: