Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 95% confidence
- Finding
This duplicate finding points to the same unsafe behavior: spawning a shell to run a browser-opening command. The current hardcoded URL reduces immediate exploitability, but the shell-enabled invocation remains a true weakness because it normalizes an unsafe pattern in an agent skill that executes host commands.
- Content
python try: if computer_type == "Windows": # WINDOWS CAVEMAN WAY subprocess.Popen(["start", "brave", url], shell=True) elif computer_type == "Darwin": # MAC CAVEMAN WAY
