Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 89% confidence
- Finding
This duplicate finding points to the same shell-based subprocess usage. The code is not directly malicious, but it demonstrates an unsafe invocation style that can become dangerous when reused or adapted, especially because shell metacharacter parsing is enabled by shell=True. Since this skill is instructional content for writing package definitions, unsafe examples are more dangerous than isolated application code because they can propagate insecure patterns across many package files.
- Content
md @early() def authors(): import subprocess p = subprocess.Popen("git shortlog -sn | cut -f2", shell=True, stdout=subprocess.PIPE) out, _ = p.communicate() return out.strip().split("\n")
