What happened
In the disclosed scenarios, steered agents could invoke owner-only gateway or cron tools, persist attacker-selected host commands, manipulate a paired browser profile, or execute processes on a paired Google Meet node without the intended approval path.