The uncomfortable truth about coding-agent safety is that the dangerous part often does not happen at the prompt. It happens mid-flight. The agent reads a repository, absorbs a poisoned instruction from a README, follows a tool result into the wrong context, starts forming a shell command, and only then becomes