We audited authorization in 30 AI agent frameworks — 93% rely on unscoped API keys