Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, ...