Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 80% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md helper; no setting or flag changes it. System proxy settings are ignored and redirects are refused. - **Routes used:** `GET /v1/account`, `GET /v1/checks`, `GET /v1/checks/{id}`, `POST /v1/checks`, `DELETE /v1/checks/{id}`, `GET /v1/checks/{id}/events`, `GET /ping/{id}`, `POST /ping/{id}/fail`. - **Data sent:** the API key in the `Authorization` header (account and check routes only); the check id in the URL; for `create`, only `name`,
