> Agents do not self execute.

That's a choice, anyone can write an agent that does. It's explicit security constraints, not implicit.