D
Great point, and well put. Least-privilege tool scoping is only half the story if the underlying credential is still over-broad, you've just moved the risk one layer down instead of closing it. The decision identity vs. action-identity separation is honestly the part most agent security discussions gloss over. Appreciate you adding this layer to the conversation.
