DVAA is a good teaching tool because permission scoping is where most agent security actually lives, and over-broad tool access is the vulnerability people notice last. The habit that helped me was treating every tool grant as something the agent has to earn per task, not a standing capability. Did working through DVAA change how you scope tool access by default?