Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The `raw` action resolves an arbitrary name from `globals()` and invokes it if callable, which exposes more functionality than the declared interface of fixed AMiner workflows and API wrappers. While this file does not currently define obviously dangerous local callables, this pattern creates an ambient capability problem: any future helper/imported callable added to the module could become remotely reachable through user-controlled input, bypassing intended allowlists and policy boundaries.
