Picture this: your copilot writes code that queries a production database, pulls a table filled with customer data, and submits the result to an LLM for “context awareness.” The model does what you asked, but it also grabbed PII, executed unseen commands, and stored that data who-knows-where. This is the