Context-Inappropriate Capability
- Category
- Not specified by scanner
- Confidence
- 99% confidence
- Finding
The script deliberately enables high-risk engine flags such as '--dangerously-skip-permissions' and '--dangerously-bypass-approvals-and-sandbox', which remove user-approval and sandbox controls before launching autonomous coding agents. In the context of a persistent squad manager that can run unattended in tmux and operate on project directories, this materially increases the chance of destructive filesystem changes, secret exposure, or arbitrary command execution without meaningful human review.
- Content
