Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The background worker forwards any incoming `SUI_AGENT_REQUEST` message's `method` and `payload` directly to a privileged local server, with no allowlist, authentication, authorization, or user confirmation. In an extension architecture, this creates a broad RPC bridge from content-script reachable code to localhost services, which can expose sensitive wallet or agent functionality and let untrusted pages indirectly drive local actions.
