> At a bare minimum, the agent must have the ability to: read files, execute programs, and make HTTP requests.

That's one very short step removed from Simon Willison's lethal trifecta.

I'm definitely not running that on my machine.

The way this is generally implemented is that agents have the ability to request a tool use. Then you confirm "yes, you may run this grep".