And with security it's always best to assume the worst case (unless you're certain that something is safe) because that would lead you to add more safeguards rather than less.
Unclear if each datasource agent is ALSO AI based though, in which case it has just pushed the same concern down the line one hop.