The agent runs as your user. Everything else has to be honest about that.
It has your shell, your filesystem and your keys. Any mechanism installed by writing configuration — an MCP entry, an environment variable, a harness hook — can in principle be un-configured by a process holding the same privileges. Tools that promise to intercept their way to safety are quietly relying on the agent’s cooperation.
Akasha does not make that claim. Its strongest guarantee is possession, not interception: a secret that exists only inside the vault has no plaintext left anywhere to steal. Getting around the interception layers wins nothing, because there is nothing on disk to find. The weaker tiers above that — owning the agent’s environment, gating each operation — are labelled as what they are, drift protection rather than a cage.
That distinction is the whole design, and the threat model states plainly what each tier does and does not buy you.