Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The handler example uses eval() on tool-controlled input (call.args['expression']), which can execute arbitrary Python code rather than safely evaluating math. In an SDK reference, readers are likely to copy this pattern into real agents, turning untrusted model- or user-derived input into direct code execution.
