What are the proper permissions for an agent? An agent shouldn't be able to read ~/.ssh, but that means a bash tool that spawns `cat` is different than one that spawns an ssh client. I don't allow my agents to use git commit, except sometimes I ask an agent to split up a complicated branch that I can't be bothered to split myself. rm'ing intermediary files is fine, but rm'ing committed files is bad, unless the agent has done *.bak renaming and is cleaning up itself, etc.
I don't think "proper" permissions are possible without dramatically limiting the way people use these tools.
I don't think "proper" permissions are possible without dramatically limiting the way people use these tools.