Directly relevant to Dan’s ThinkPad setup. The security boundary has shifted — agents read untrusted content, call tools, and use credentials. The article maps 5 critical trust boundaries (identity, execution, instruction, persistence, supply chain) and a repeatable attack chain. High-ROI defenses: dedicated identities with least-privilege, isolated execution, tool gating, egress allowlisting. Worth reviewing against the current MCP + Claude Code setup.