Shell execution
subprocess, os.system, shell=True, and command argument patterns.
Krahanos uses deterministic Python AST analysis to surface capabilities. A finding is a reason to review code and intent, not proof that a vulnerability exists.
subprocess, os.system, shell=True, and command argument patterns.
Database execute, insert, update, delete, and write SQL signals.
File deletion and other operations that can remove resources.
Outbound network clients plus environment and secret access.
eval, exec, and compile capabilities.
MCP capabilities, destructive tools, and tool registration.
Network destinations controlled by variables instead of fixed literals.
Credential-like constants assigned directly in source.
Destructive tools without approval checks and dangerous capability combinations.
Variable data passed into LLM calls and system prompts stored in source.
Broad IAM permissions and unsafe deserialization calls.