A coding agent that can run bash on your laptop is a remote shell on localhost. It has that threat model whether or not anyone designed for it — browser drive-bys, DNS rebinding, curl | bash, the twenty years of localhost-daemon mistakes the web already made and wrote down.
Last week wren.wtf published a teardown of opencode: — gate /mcp against the browser drive-by
— refuse unverified
curl | bash installers in non-interactive contexts+ — the interpreter footgun: warn, then confine (macOS Seatbelt, Linux bubblewrap)
. Then run the four questions against whatever agent runs commands on your machine. You'll find something.
SOCIAL SHARE CARD GENERATOR