When I started building Agent_Sudo, I thought the hard part would be approvals and policy enforcement.
I was wrong.
The hard part was discovering all the ways real agents behave once they start interacting with real tools, real runtimes, and real users.
Over the last week I dogfooded Agent_Sudo against actual agent workflows and found four surprising problems:
1. Agents Can Bypass Governance If The Runtime Gives Them Native Tools






