It is not sufficient to secure VM the agent has CLI permissions on.
We must also secure GPU and CPU nodes on API side which generate LLM tokens.
Why? The inference server isn't a harness, it's tokens in, tokens out. That's different from a harness.
Why? The inference server isn't a harness, it's tokens in, tokens out. That's different from a harness.