Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The document explicitly recommends removing file-read restrictions and shows an example where the agent can 'read anything'. That guidance broadens agent access beyond least-privilege and can expose secrets, credentials, personal data, and unrelated workspace content if adopted in a real system.
