Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The script automatically adds every created agent to tools.agentToAgent.allow, expanding privileges beyond the stated purpose of provisioning agents and binding them to messaging channels. This increases lateral interaction capability for all new agents without explicit operator consent, which can broaden the blast radius if one agent is misconfigured, prompt-injected, or compromised.
