I am wondering how it solves the security issues: I saw opt-in, file permissions and SSRF in README, but I do not see: domain allowlist; human approval before submiting/deleting; persistent audit record after operations; how to revoke a previously granted access; The prompt injection may also induce the agent to perform write operations. Reuse the real user-login session also delegate the user's full authority to the…
I bet it doesn't. It's one gaping security hole.