AGENTFORCE-MCP-10: MCP Tool Code Execution Sink
๐จ Critical ยท MCP Supply Chain
Detects shell/process execution in MCP server code whose command comes from non-literal input (tool arguments) and is reachable from a tool handler across files, plus eval/exec sinks in MCP server source. Test code and MCP client code are excluded.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-MCP-10 |
| Severity | Critical |
| Category | MCP Supply Chain |
Remediationโ
Do not pass tool arguments to a shell. Map tool inputs to an allowlist of fixed commands, use execFile/spawn with shell:false and literal executables, and require user confirmation for command execution. A blocklist of command names is not a sandbox.