Tool Parameter Abuse
High
- Category
- Tool Misuse
- Content
��� S��r��X*��+��F�LA2�����������&�/s��{����ّ �uQ�7]��4 �즉?-٦^�3�(�2h2W}��ZEr�U�P�T���֯�:TO�A?4�-�i~��1u�'�",|�� P�X�n�T�%��tv:��h[0[e�d���DTn+苨��J3�f9&���?�K �k K�y+j �xċ�yUۓ=�F��CI�(��r� �:&���@S�gi��RԘy�����g\��- Confidence
- 89% confidence
- Finding
- Unlike the other TM1 hits, this file does contain an actual active element: an embedded OpenAction JavaScript object that executes app.execMenuItem('ShowHideBookmarks') on open. Even though the script is benign in effect, active document-triggered JavaScript is dangerous in agent or automated document-processing contexts because it normalizes executable content inside inputs and can be swapped for more harmful actions in similar workflows.
