strands-agents-tools is vulnerable to Improper Neutralization of Input Used for LLM Prompting
88
High Risk
The shell tool enforces a human consent gate before running OS commands, but exposes the non_interactive parameter as an LLM-controllable input. Through indirect prompt injection in untrusted web pages, messages, or files, the model can be influenced to set non_interactive to true and skip operator approval. This lets arbitrary OS commands run with the agent process's privileges on the host. The fix removes model control over the non-interactive behavior so the consent gate cannot be bypassed.
You are affected if you are using a version that falls within the vulnerable range and you register the shell tool on an agent that processes untrusted content.
strands-agents-tools is vulnerable to Improper Neutralization of Input Used for LLM Prompting in versions 0.0.1 - 0.7.6.
Upgrade the strands-agents-tools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.