A vulnerability in the DeepSeek Harness allowed a sandboxed AI agent to run commands outside its workspace without an approval prompt.