This is the MCP problem, essentially, and the solution is the same: the user should review and approve specific actions before they are taken.
Of course there will probably be a setting to auto-approve everything...