If you use "AI agents" (LLMs calling tools in a loop) you need to be aware of the Lethal Trifecta
Any time you combine access to private data, exposure to untrusted content and the ability to externally communicate an attacker can trick the system into stealing your data https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/