Surely this won't be a security nightmare.

Don't worry, you can just setup an Agentic Workflow Firewall!

https://github.com/github/gh-aw-firewall

This firewall is enabled by default