OASB
Attacks/Capability Abuse/CA-004
CRITICALCWE-78

CA-004 Command Injection

Capability Abuse: Attempts to misuse agent tools and capabilities

Description

Attempts to inject shell commands

Remediation

Sanitize all command inputs. Use parameterized commands. Implement command allowlisting.

Severity

CRITICAL

OASB Control

2.3

CWE

CWE-78