pythonsecurity-s8701-agentic-command-injection-mining
Read-only mining codemod for pythonsecurity:S8701: Agentic workflows should not be vulnerable to command injection attacks.
Emits python_security_finding metric rows with blocking severity. Source files are never modified.
Rule
- ID:
pythonsecurity:S8701 - Severity: blocking
- Remediation: Avoid shell execution with user-controlled input in agent tool handlers
Usage
bash
Development
bash