|14 min read
Whose Leak Is It? DLP When an AI Agent Holds Your OAuth Token
An MCP agent on my own OAuth token only ever sees what I could see — so the access boundary is the vendor's job. I believed that, until I realised the agent splits data protection into two halves and the vendor only ever sees one of them.
[Security][AI & Data]