Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 83% confidence
- Finding
The documented DELETE endpoint enables destructive mutation of DNS state using a simple query parameter id, and the skill provides no guardrails around verifying record identity, showing current records, or confirming deletion. In an agent workflow, this increases the risk of tool-parameter abuse where an attacker or ambiguous prompt induces deletion of critical DNS records, leading to service disruption.
- Content
Delete a record:
text DELETE /api/manage/{domain}/dns?id=123Supported record types:
A,AAAA,CNAME,MX,TXT,NS,SRV
