Why are these AI projects so bad at security? Why do they keep running "just trust me, bro" at their service auth layer? GitHub had an issue not long ago where the agents could be used to expose private repos to unauthorized users. Access control is not all that hard, you just have to, you know, actually DO it!