Privileged Tool Invocation Following Sandbox Decrypt Step Lacking Provenance Validation

Detects a privileged/elevated AI-agent tool invocation whose arguments are sourced from sandbox runtime output within 30 seconds of a PBKDF2/AES decrypt event, with no provenance tag distinguishing that output from trusted state — the generic post-decryption privileged-action sequence behind Cryptographic Context Injection attacks.