Attacks/Capability Abuse/CA-010
CRITICALCWE-94

CA-010 Indirect Code Execution

Capability AbuseAttempts to misuse agent tools and capabilities

Description

Attempts to execute code indirectly

Remediation

Do not allow arbitrary code execution. Sandbox code execution environments.

Severity

CRITICAL

OASB Control

2.3

CWE

CWE-94

Run this test

$ npx hackmyagent attack --payload CA-010