One permission wasn't enough. The AI agent's token became a backdoor.
A developer granted an ops agent write access to pull requests, but the underlying token had push permissions too, creating an unintended security vulnerability that could compromise entire systems.
September 26






