Review agent · Web & injection
Command & code injection
Checks whether user input reaches a shell, eval or template-evaluation sink.
Illustrative example of how this agent reviews a finding.
Why this agent matters
Command and code injection is usually game over: the attacker runs code as your application. The 2017 Equifax breach began with an injection flaw in Apache Struts.
Calls to subprocess or eval are common and often harmless — a fixed command, an argument list with no shell. This agent checks whether input is user-controlled and whether arguments are passed safely, so real sinks stand out.
What it checks
- os.system, subprocess with shell=True, popen and backticks
- eval / exec and dynamic code evaluation
- Server-side template injection
- Arguments built from request data
When it marks a finding as a likely false positive
- The command is fixed, or arguments are passed as a list without a shell
- Input is validated against an allow-list before use
The fix it suggests
- Argument vectors without shell=True
- Removing eval / exec
- Allow-list validation of any input that must reach a command
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Is every subprocess call flagged as dangerous?
No. A fixed command or an argument list with no shell is marked a likely false positive. The agent focuses on user-controlled input reaching a shell or evaluator.
Related agents
- SQL injection — Decides whether attacker-controlled input actually reaches a SQL or NoSQL query unparameterized.
- Cross-site scripting (XSS) — Checks whether untrusted data is rendered into HTML or JavaScript without contextual encoding.
- Server-side request forgery (SSRF) — Checks whether a server-side request can be pointed at a host the attacker chooses.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Command & code injection agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free