This looks really interesting. I'm curious to learn more about security around this project. There's a small section, but I wonder if there's more to be aware of like prompt injection
However, this does not help if a person gives access to something like Google Calendar and a prompt tells the LLM to be destructive against that account.