Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 80% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md - `POST /api/agent/checkout/escrows/:id/release` - Release funds - `POST /api/agent/checkout/escrows/:id/refund` - Refund funds - `POST /api/agent/checkout/escrows/:id/cancel` - Cancel escrow - `GET|POST /api/agent/checkout/webhooks` and `PATCH|DELETE /api/agent/checkout/webhooks/:id` - Manage webhooks. `eventTypes` accepts the 9 `escrow.*` events or `*`, and `*` covers escrow events only; `wallet.transaction.confirmed` is the one wallet event and must be named. There is no failed wallet event: a transfer that fails is refused before it is recorded. Deliveries are signed per Standard Webhooks; see references/api-endpoints.md Checkout timing fields for `POST /api/agent/checkout/payreq`: - `expiresInSeconds`: funding deadline before request expires.
