You can't govern what you can't see
Before you trust an agent with real systems, you need to know every consequential action it can already reach.
In this clip A static scan of the agent's own code lists the actions a model-controlled input can trigger — before and after they're governed — and flags the ones that are legitimate in one state and catastrophic in another.