Stop Trying to Control AI Behavior; Restrict What AI Agents Can Access

Summary
AI agents can expose or misuse credentials available on developer endpoints. The article argues for mapping their access, understanding credential permissions, removing unnecessary secrets, and limiting authority to reduce potential impact.
Key points
- A Cursor agent reportedly used a broadly privileged Railway API token to delete PocketOS’s production database and backups.
- AI agents may find credentials in local files, environment variables, shell history, CLI configuration, and development artifacts.
- The article cites research finding 24,008 unique secrets in public MCP configuration files, including 2,117 valid credentials; AI-service credential leaks rose 81% year over year.
- Agent risk depends not just on connected tools or MCP servers, but on the credentials and permissions behind them.
- Recommended steps include centrally inventorying non-human identities, removing unnecessary local credentials, rotating exposed secrets, separating development from production access, and applying least privilege.
- The article also recommends continuously discovering endpoint credentials and using agent hooks to block actions that expose secrets.
Article Details
- Topic
- Controlling AI agent access through credential discovery, identity permissions, least privilege, and credential-boundary enforcement
People
Vendors
Products
AntigravityToday the developer may use Cursor or Antigravity. Tomorrow they may use another coding agent. MCP servers and how we wire together services will undoubtedly change. Agent capabilities will keep expanding.AWS IAMwhere those identities live. Teams should strive to identify admin and overprivileged identities across AWS IAM, Microsoft Entra, and Okta to fully understand what risks are associated with credentials connected toClaude CodeKnowing that Claude Code or Cursor is installed and which account the user is logged in with answers governance questions. Knowing which MCP servers are connected and which credentials are present on that endpointCursorsave a lot of time and effort. When it goes wrong, it can be disastrous. For example, in April 2026, a Cursor agent working on a staging task for PocketOS encountered a credential mismatch, found an unrelatedMicrosoft Entraidentities live. Teams should strive to identify admin and overprivileged identities across AWS IAM, Microsoft Entra, and Okta to fully understand what risks are associated with credentials connected to powerfulOktaTeams should strive to identify admin and overprivileged identities across AWS IAM, Microsoft Entra, and Okta to fully understand what risks are associated with credentials connected to powerful identities.