what stops the agent from echoing the secure storage?
what i see is that you give it a pass manager, it thinks, "oh, this doesn't work. let me read the password" and of course it sends it off to openai.
OpenAI is not the worst it could or would send it to.
OpenAI is not the worst it could or would send it to.