Typically agents are not operating as a distinct user. So they have the same permissions, and thus credentials, as the user operating them.
Don't get me wrong, I find this framework idiotic and personally I find it crazy that it is done this way, but I didn't write Claude Code/Antigravity/Copilot/etc