Great question, Kartik! The idea is to capture the user's original request as the source of authority, then evaluate tool effects against what that request actually permits — not just which tools the agent can access. The tricky part is translating natural-language intent into explicit constraints without assuming permissions the user never granted. That's one of the problems I'm exploring with AgentSec!
