This blog post discusses the challenges of securing coding agents, arguing that many security measures are ineffective ('security theater'). It highlights that once an agent can run code, protecting data becomes extremely difficult, suggesting that cutting network access renders the agent mostly useless. Allow-listing domains can provide some security but comes with limitations and potential workarounds.