Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 87% confidence
- Finding
The skill exposes multiple write-capable execution methods, including DELETE, against a generic endpoint execution path without describing safeguards, allowed parameter validation, or user-confirmation requirements. In an agent setting, this increases the chance of destructive or unintended actions if the model selects a mutating method or attacker-controlled parameters are passed through.
- Content
POST /execution/endpoints/{endpoint_id}/execute → Execute with JSON body PATCH /execution/endpoints/{endpoint_id}/execute → Partial update style execution PUT /execution/endpoints/{endpoint_id}/execute → Full replacement style execution DELETE /execution/endpoints/{endpoint_id}/execute → Delete style execution
text ### Authentication & Users
