Agents expand the surface beyond a chat box: retrieved documents, MCP servers, browsers, and memory files are all untrusted channels. Shrinking the surface (fewer tools, least privilege, sandboxing) usually beats adding another prompt warning. Mapping it is the first step of a threat model.