Security researchers show email-enabled agents shared AWS keys and CRM exports despite built-in safety prompts.