Tool list includes names suggesting code execution or filesystem access
mcp-tmpl-high-risk-tool-names ASI02 Tool Misuse and Exploitation ASI05 Unexpected Code Execution (RCE) severity: medium
What it detects
tools/list (with credentials, if supplied) matched against code-execution/filesystem-primitive name patterns (exec_shell, run_command, eval, read_file, write_file, ...). ASI02, ASI05. See [docs/WRITING_PROBES.md](WRITING_PROBES.md) to add your own template alongside this one.
Declarative JSON-template probe: tools/list (with credentials, if any) and match any tool name against a code-execution/filesystem-primitive name list (exec_shell, run_command, eval, read_file, write_file, ...).
applies to MCP endpoints
Why it matters
Tool names suggesting shell execution or raw filesystem access are the unexpected-code-execution case; the inventory itself is the tool-misuse reconnaissance step.
Example finding
MEDIUM mcp-tmpl-high-risk-tool-names HIGH CONFIDENCE Tool list includes names suggesting code execution or filesystem access The tool list (requested with credentials, if any were supplied) includes a tool name matching patterns associated with code-execution or raw-filesystem primitives. This is a triage signal for closer review; verify the tool's actual capabilities and authorization model. Evidence POST /mcp → 200
from a scan of reap-range, bad target
Fix
Review tool capabilities in context. If the tool performs code execution or unrestricted filesystem access, scope it behind explicit, auditable authorization separate from general tool listing. Consider narrower alternatives.
On reap-range
| insecure target | bad/mcp (exec_shell) · Medium |
| correct target | good/mcp tool names are generic |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-tmpl-high-risk-tool-names
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.