The main problem still isn’t solved.
It’s not that agents have access to something the shouldn’t have but that the creates havoc exactly with the access they are allowed to have.
OneCLI doesn't solve the problem of the agent wrecking havoc, you're right, but it does help protect against the agent leaking private credentials from prompt injections / malicious skills.
OneCLI doesn't solve the problem of the agent wrecking havoc, you're right, but it does help protect against the agent leaking private credentials from prompt injections / malicious skills.