Vague Triggers
Medium
- Confidence
- 95% confidence
- Finding
- The trigger phrases are broad enough to auto-invoke a capability that performs arbitrary command execution on the host, including requests like "run on host" or "outside container." In this context, loose matching is dangerous because accidental or indirect activation can cross a trust boundary from container to host and enable destructive actions on host files, services, or Docker state.
