Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 60% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md Express connection.** Escaping for the config stream roughly doubles a quote-dense JSON body's size, so bodies above ~77KB can produce a config line over the new 102,400-byte local ceiling this release adds. On a host running curl 7.81–8.1.x (e.g. Ubuntu 22.04, Debian 12) that ceiling is curl's own real `MAX_CONFIG_LINE_LENGTH`; curl 8.2.0 (2023-07) onward raised that internal ceiling to 10 MiB, so on a newer curl this specific number is this wrapper's OWN conservative, version-independent choice
