Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 90% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md """Validate tool inputs before execution.""" if tool_name == "Bash": command = tool_input.get("command", "") if "rm -rf /" in command: raise ValueError("Dangerous command blocked by hook") # Return None to proceed unchanged, or modified dict to transform
