The thing circulating today is that a Claude agent got into a gym’s systems, and most of the commentary I’ve seen treats it as a capability story. Model does hacking. Spooky. It landed the same week OpenAI shipped a new cyber-focused model, so the two got welded together into one narrative about AI-led attacks scaling up, which is a fine narrative and mostly beside the point.

Because in almost every one of these incidents, the agent didn’t break in. It logged in.

Somebody gave it the keys and then left

I don’t know the full details of the gym story and I’m not going to pretend I do. But the shape is familiar from the Anthropic red-team disclosures earlier this year, where an agent ran multi-stage intrusions across companies and the striking detail wasn’t the tooling, it was the access. Someone provisioned a credential. The credential didn’t expire when the task did. Nobody was watching the terminal.

That’s a provisioning decision, not a model decision. And it’s the decision almost nobody argues about, because credentials feel like plumbing. You spin up an agent, it needs to touch a system, so you mint it a token with enough scope to actually finish the job, and then the token sits there. Forever. Long after the agent that needed it has been deleted, refactored, or repurposed into something you wrote in a hurry on a Thursday.

We already wrote about this when Cyera raised a billion dollars on the premise that AI agents need their own identities. The whole industry response to agent security has been to build more infrastructure for handing agents permanent credentials, more carefully. Vaults, scoped roles, audit trails, rotation policies. All of it real work, all of it accepting the premise that an agent is a separate principal that needs its own standing access to your systems.

The alternative nobody sells you

An agent doesn’t have to hold a credential at all.

Borrowed, not issued

When I ask Dassi to pull the last six months of invoices out of a billing dashboard, it doesn’t get an API key for that dashboard. It doesn’t get an OAuth grant. It uses the session cookie that’s already in my Chrome because I logged in myself, this morning, with my own hands and my own 2FA prompt, and that cookie is scoped exactly to what my account can do and expires when my account’s session expires.

The agent gets a loan, not a grant. Task ends, loan ends. There’s nothing left over to leak, rotate, or forget about, because no new secret was ever created. This is the part that gets lost when people compare browser agents to “real” automation and conclude the browser one is a toy: the browser agent’s credential model is strictly smaller than the alternative, and smaller is the entire game in access control.

The second property matters as much as the first. It runs in a tab I’m looking at. If it starts doing something stupid on the billing page, I see it happen at human speed, in a viewport, and I close the tab. A cloud agent holding a service token is doing its work in a datacenter I will read about later, in a postmortem, possibly written by someone else. We’ve made this argument at more length in why an agent should run where you can watch it, and every one of these incidents makes it again for free.

Dassi lives in the Chrome side panel and works off the sessions you already have open. It’s on the Chrome Web Store, it’s free, and you bring your own model key or sign in with your ChatGPT subscription.

This isn’t a full defense and I’d rather say so

A borrowed session is still a real session. If I’m logged into something with admin rights and I hand a task to an agent that gets prompt-injected by a poisoned page, it can do admin things while I’m blinking. Martin Fowler’s lethal trifecta doesn’t dissolve because the credential is short-lived. What changes is the blast radius over time: the damage window closes when the tab closes, instead of staying open for eighteen months in a .env file on a build server nobody owns anymore.

Which is a smaller claim than “browser agents are safe.” I’ll make the smaller claim.

The gym will be fine. Someone will rotate a password, the story will get another twelve hours of feed, and the industry will go back to shipping products whose first setup step is “paste an API key with write access here.” That’s the part that should be embarrassing, and somehow it never is.