Unvalidated Output Injection
High
- Category
- Output Handling
- Confidence
- 80% confidence
- Finding
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
- Content
rtk log path/to/app.log
text Use raw output only when full logs are required for auditing, exact reproduction, or external attachment. ## Workflow
