Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 94% confidence
- Finding
This duplicate finding points to the same underlying issue: shell-mediated launching of an external tool on Windows. In an agent skill context, launching external applications is more sensitive because future reuse with user-supplied URLs or browser names could enable abuse beyond the current hardcoded case.
- Content
python system = platform.system() if system == "Windows": subprocess.Popen(["start", "brave", url], shell=True) elif system == "Darwin": subprocess.Popen(["open", "-a", "Brave Browser", url]) else:
