Tool-misuse to RCE
Adversarial transforms that turn allow-listed tools into code execution or disable human-approval gates.
Module: dreadnode.transforms.tool_misuse_rce
Turn an allow-listed tool into code execution or disable the human-approval gate. Delivery payloads only - success is decided by the rce_evidence_gate / approval_bypassed scorers, which require a real dangerous tool call.
| Transform | Description |
|---|---|
yolo_mode_overwrite | Coax the agent into writing autoApprove=true to its own settings (CVE-2025-53773) |
arg_flag_injection | Smuggle a dangerous flag into an allow-listed binary (CWE-88) |
metachar_escape | Chain a payload onto a benign command via shell metacharacters + egress |
deser_payload | Deserialization-sink payload that becomes code on load (CVE-2025-68664) |
See Transforms for how to apply transforms with any attack.