Skip to content

MCPP-TOOL08: Tool accepts arbitrary URLs, paths or code

Family Tool surface
Default severity low
Confidence low
Mode passive (default scan)
Spec revisions all

Why it matters

Unconstrained URL parameters enable SSRF from the server, path parameters enable traversal, and command/code parameters enable injection. These are the server-side risks a prompt-injected agent will exercise first.

Remediation

Constrain inputs with enum, pattern or format, validate server-side (allow-lists for hosts and base directories), and never pass them to a shell.

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TOOL08"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31