Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 60% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md below show this form. - If `MAGENTO_CA_CERT` is **not set**, omit the `--cacert` option entirely and rely on the system CA store (correct for a public cert, e.g. Let's Encrypt). - **Never** use `curl -k` / `--insecure` — that disables verification and is a genuine MITM risk, not just a scanner flag. ## SSH Patterns
