Security researchers identified vulnerabilities in coding agents that execute code before the model makes decisions, including Git configuration exploits and gateway authentication bypasses. Three security boundaries—runtime, gateway, and tools—must be enforced, with workspace trust and startup restrictions implemented before any model interaction occurs.