Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 93% confidence
- Finding
The skill establishes a mechanism for the agent to prepare a host-executed script and have a human/operator run it outside the sandbox. Even though it says to include only Docker commands, this creates a trust bridge from untrusted agent output to host execution, and Docker commands themselves can be highly privileged via mounts, host networking, privileged mode, or access to existing containers.
- Content
md - Un comando por línea, con `set -e` implícito (fallo detiene ejecución) - Incluir solo comandos Docker; NO comandos arbitrarios de host - Comentar cada bloque con propósito 3. **Hacer ejecutable** — `chmod +x /workspace/host-commands.sh` 4. **Registrar en COMMS** — Escribir bloque `WORKBOARD_BLOCK` con: - REASON: "Docker operation required — host-commands.sh ready" - COMMANDS_FILE: `/workspace/host-commands.sh`
