An academic review of agentic offensive-security systems shows a hard truth for defenders: automation can widen the blast radius if the tool itself is not tightly contained.