Picture this: your coding copilot just suggested a query that hits production data. Nice productivity boost, terrible security nightmare. Autonomous agents now spin up pipelines, read internal docs, and talk to APIs like seasoned engineers. Yet most of them work without real oversight. They can expose PII, leak API keys,