Token Optimizer MCP: OS command injection in smart_user via username in get-user-info (CVE-2026-55157) | HOL Guard CVE