A few weeks ago I gave an LLM-driven coding agent the ability to run shell commands on a scratch server, and within ten minutes of unconstrained experimentation it tried to curl a metadata endpoint, write outside its working directory, and read my shell history file. None of that was malicious —...
Source: [Dev.to](https://dev.to/devio_4040/your-ai-agent-has-shell-access-heres-how-i-test-what-it-can-actually-touch-21gm)