Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The calculate tool evaluates attacker-controlled input with JavaScript eval(), which can lead to arbitrary code execution in the server process rather than simple arithmetic. In an MCP tool context, this is especially dangerous because the agent can be induced to pass untrusted expressions into the tool, potentially enabling command execution, data theft, or process compromise.
