AI coding agent security: a checklist for your own machine
What a coding agent can reach, the boundary to put around it, what it writes to disk, how to check what it already ran, and how to scope the tokens it holds. Fourteen steps, in the order worth doing them.