The dangerous thing about CI agents is not that they can write code.

It is that they run in the place where we already concentrate trust.

CI has repository access. CI has tokens. CI has build logs. CI can fetch dependencies, publish artifacts, comment on pull requests, open issues, deploy previews, and sometimes touch production systems. It is...