Even if you have exclusively granted your agent read only privileges, it might still attempt to dispatch an email. Should this happen, Vic intercepts and halts the action long before the command ever reaches Gmail. It does not matter how persistently the agent repeats the prompt, because the system will automatically and consistently reject the attempt. Every single unauthorized action is decisively shut down.

https://www.civic.com/news/agent-security-layer