Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script exposes an agent-accessible command that attempts to complete orders by submitting a transition request with role set to "admin". Even if the backend is supposed to reject unauthorized requests, embedding privilege-escalation behavior in client tooling normalizes and facilitates abuse, and becomes critical if the server trusts caller-supplied roles.
