Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The proxy defaults to CZ_INTERRUPT_DECISION_MODE=auto_approve and later converts interrupt_request messages into interrupt_decision approvals automatically. In a bridge component, this means a remote agent can obtain tool/action execution approval without an explicit local user confirmation step, which materially expands the trust boundary and can enable unauthorized actions through downstream tools.
