1. What is the principle of least privilege applied to an agent's tools?
2. Why place an approval gate before irreversible actions?
3. What does an output guardrail typically validate?
4. How does sandboxing a code-execution tool reduce risk?
5. What is an input guardrail meant to catch?
6. Why is a step or tool-call budget a useful guardrail?
7. What is the containment strategy of running an agent with a 'dry-run' mode?