Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- In --sample mode, the script spawns another local script via execSync and forwards the entire process environment. That expands this file’s effective privilege boundary from local JSON generation to arbitrary child-process execution with inherited secrets or credentials, which is unnecessary for producing strategy output and increases the blast radius if the sibling script or environment is compromised.
