what's to stop an agent creating an outbound call with the var to a malicious endpoint? (unless you whitelist what it has access to)
The main reason a "proxy-managed" env var is set is because most CLI tools assume if the env var is set, auth is set. If the env var is unset, it will assume auth needs to occur. Fortunately, most don't do a pattern matching on what the value actually is.
There's also an ability to create kits where you can setup credential injection into other services as well.