This finding matters because the real failure is usually not the prompt injection itself. The decisive failure is the execution sink. If the system lets model output become executable shell text, then any poisoned instruction path can inherit the runtime's authority.
For Zealynx, this should be treated as a prompt-to-sink issue, not generic prompt injection. Auditors should map exactly which inputs can influence the command and whether the human approval covered the actual arguments.