The Permission Boundary Myth: Why Authorized Doesn't Mean Appropriate for Coding Agents
Coding agent security has a framing problem. Most security conversations around these tools center on the wrong question. 'Did the agent have permission to do that?' is a reasonable place to start, but in the context of autonomous AI systems, it's not where the risk actually lives. In Zenity Labs' research into the coding agent threat model, the pattern that keeps surfacing isn't that agents are doing things they aren't allowed to do.