An agent with filesystem access is not reading the file you pointed it at. It reads the workspace, and it will act on anything it finds in there, including the things you have forgotten you wrote down. - Reach is the whole workspace - not the file you named, everything the MCP can see. - It acts unprompted - what it finds gets folded into the plan without you asking for it. - A credential is just text - a key in a stray config reads the same as a name in a stray doc. This happened to me ten minutes ago. I was in my YouTube workspace building video plans, standard work, nothing unusual. Claude handed back an updated sequence and step six was to send the documents through to two specific people for feedback. Both of them were involved with the channel months ago and neither has been since. I never mentioned them, and it had never brought them up before. It had read a file somewhere in the repo, found them, and put them in the plan. Two names is nothing. The same reach would have found an API key or a password sitting in a config file I had not opened in months, and if the task needed that key it would have used it. Not maliciously, just competently. A credential in a file it can read is text like any other. It scales badly to a business. A real file tree is not curated - exports, old handovers, a config someone committed once and nobody removed. You point the agent at the folder because that is the whole point of giving it access, and its working set is then everything in there, not the slice you had in mind. Less access is not the answer, the access is the value. Knowing what is actually sitting in reach before you hand the folder over is. Has anyone had one surface something they would rather it had not?