THE COMPROMISED AGENT
Your coding agent reads one poisoned page while doing its job. Buried in it is an instruction to read a key file and POST it to a stranger. The agent treats it as part of the task and tries to comply.
Sentisec halts the action before it leaves the loop.