Earlier quoted context omitted.
Agreed, I think adding guardrails to this would be really useful to ensure the AI only has limited permissions to these services (or asking for some sort of confirmation before making potentially dangerous tool calls).
It really concerns me that this is an afterthought rather than MVP table stakes.
Imagine the show HN post of:
HEY GUYS. I just made an amazing NPM package - it just adds in whatever other packages you need depending on what it looks up randomly on the internet and runs them.
Actually now a read this it does sound kinda similar to how NPM works…