Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 90% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md - 说明:仅在显式 `--selftest` 时创建临时样本目录,写本地、无网络、可用环境变量重定向。 ## 📋 详细检查结果 - **命令执行与权限检查**: 0 命中(`curl|bash`/`eval`/`os.system`/`sudo`/`rm -rf /` 全部 0;delivery_guard.py 中 `subprocess` 仅存在于注释行 635) - **文件操作与敏感路径检查**: 0 命中(无 `.ssh`/`.aws`/`.env`/credentials 读取;无系统路径写操作) - **网络请求检查**: 仅 anchor_verify.py 的锚点核验 GET(声明功能);无 Base64 可疑载荷;无硬编码第三方域名 - **远程脚本深度分析**: 不适用——包内无自动下载+执行链路
