Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The proxy defaults CZ_INTERRUPT_DECISION_MODE to auto_approve, causing interrupt/tool-execution requests from the remote Studio agent to be approved without explicit user confirmation. In a skill whose stated purpose is task/query/job operations via a JDBC-backed Studio connection, this expands authority beyond simple proxying and can authorize unintended side-effecting actions if the remote agent issues tool/action requests.
