Agree, anything that agent has access to is like giving it to malicious user. Especially when agent is exposed to different users that should have different permission levels