Of your five questions, the first one has an answerable shape: "How much network access should an coding agent have?" The defensible default is none, then an allowlist per task, package registries and the repo host for a build task, nothing else, because prompt injection only becomes exfiltration when there is an open egress path. The messier half of that question is what rides in with the agent: skills, plugins, and MCP servers all widen network reach and are installed with far less scrutiny than any dependency would get. When we aggregated every published security audit of agent skills for our August 2026 census, the five auditors could not agree on what unsafe even means, with fail counts from 697 listings to zero, which says the tooling for your audit question barely exists yet: skillselion.com/research/agent-skill-security-cen… (disclosure: I run Skillselion). Does the full guide take a position on egress allowlists, or stop at logging?
Of your five questions, the first one has an answerable shape: "How much network access should an coding agent have?" The defensible default is none, then an allowlist per task, package registries and the repo host for a build task, nothing else, because prompt injection only becomes exfiltration when there is an open egress path. The messier half of that question is what rides in with the agent: skills, plugins, and MCP servers all widen network reach and are installed with far less scrutiny than any dependency would get. When we aggregated every published security audit of agent skills for our August 2026 census, the five auditors could not agree on what unsafe even means, with fail counts from 697 listings to zero, which says the tooling for your audit question barely exists yet: skillselion.com/research/agent-skill-security-cen… (disclosure: I run Skillselion). Does the full guide take a position on egress allowlists, or stop at logging?