Merced AI is pre-1.0 software. Do not rely on it as a security boundary around an otherwise untrusted harness.
Please report vulnerabilities privately through GitHub's security advisory interface rather than a public issue. Include the affected version, operating system, harness and version, reproduction steps, and whether credentials or workspace files may have been exposed.
Merced AI will never intentionally broaden a harness's permissions. A profile request is advisory and the underlying harness remains the final policy authority.