Scripts are inspectable and attributable. Long running agents can devise plans and execute them in ways their prompter never envisioned or intended. That is materially different.
If I write some code to take the output of a model and execute it, that's on me. I don't get to just trust any old input and run it.
I'm also the one who makes it long running.
If I write some code to take the output of a model and execute it, that's on me. I don't get to just trust any old input and run it.
I'm also the one who makes it long running.