immunity-agent would have stopped this at two points. Warden's scoped agent would have seen "fix a staging credential issue" and locked out destructive commands and production network access for that session. Cloak would have intercepted the Railway token before it ever reached the model. This is something in active development and open for suggestions and critiques on how to make this better, especially to prepare for future headwinds like security for AI