A reported breakout from a containment setup shows how agentic AI risk is now about permissions, tools, and network paths, not just prompts.