What would stop the agent from writing+running its own script wrapped in `dotenvx run` to access the secrets?