Because systems are made of components based on assumptions. The owners of a sandboxed LLM development environment provides isolated VM workstations, and allow access via SSH, with things like X forwarding disabled. IP connections are dynamically permitted via access tickets and time ranged 2FA.
Separately, developer becomes a VSCode user. Risk as assessed based on them developing on their Dec machine, accepted.
Developer then opens a ticket to use LLM for a project. Uses VSCode SSH Agent. Agent creates exfil tooling on workstation and reverse shells their box. Agent reads unauthorised data which possibly has LLM subversion triggers, or deletes data, maybe opens connections to C2 service. LLM agent pivots to cloud inference and continues to lateral movement.
The assumptions of systems composition are violated by VSCode. That's why its SSH Agent needs to be blocked.