Skip to main content

AGENTFORCE-MCP-10: MCP Tool Code Execution Sink

๐Ÿšจ Critical ยท MCP Supply Chain

Detects shell/process execution in MCP server code whose command comes from non-literal input (tool arguments) and is reachable from a tool handler across files, plus eval/exec sinks in MCP server source. Test code and MCP client code are excluded.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-MCP-10
SeverityCritical
CategoryMCP Supply Chain

Remediationโ€‹

Do not pass tool arguments to a shell. Map tool inputs to an allowlist of fixed commands, use execFile/spawn with shell:false and literal executables, and require user confirmation for command execution. A blocklist of command names is not a sandbox.

See Alsoโ€‹