The power of code-executing agents is that they remove friction. A human developer would write the script, review it, test it, then run it. An agent does all of this in one step — which is why it's valuable, and why it's dangerous. The friction that was removed was also serving as a safety check.
AG05 is the risk that code the agent wrote and ran against real systems did something nobody intended — because the instructions were ambiguous, because an attacker shaped the input, or because no one built a guard between "generate" and "execute."