You need to treat agents as an independent user you're allowing on your machine.
Give them their own account. Give them only the access you want them to have. If they "hack" around that, do what you'd do to any other malicious user: kick them off.
You need to treat agents as an independent user you're allowing on your machine.
Give them their own account. Give them only the access you want them to have. If they "hack" around that, do what you'd do to any other malicious user: kick them off.