How a coding agent was tricked into writing SQL injection-prone code, installing shell tools, and maybe even stalking its user