Until you are (or if the agent runs) one privilege escalation away from the whole system being taken over.
So useradd isn't enough.