Static API scopes validate who holds a credential, not why an action is being taken, creating a critical enforcement gap where agentic lateral movement lives. Until formal intent-propagation standards emerge across frameworks like MCP, defending against scope escalation across parent-child agents requires behavioral tracking at the tool execution layer, validating every tool call against the active session context rather than just credential validity.