An agent that can only chat is easy to contain. An agent that can read Gmail, open GitHub issues, update Notion, and send Slack messages is much more useful—and much harder to secure.

The uncomfortable part is not the tool call itself. It is everything around it:

Where does the OAuth refresh token live?

Can the agent see it?

Which actions may this particular agent execute?