So the easiest solution is full human in the loop & approval for every external action...
Agents are doomed :)