| name | detecting-eval-exec-usage |
| description | Scan a source tree for dynamic-code-execution APIs that an attacker
can hijack: Python eval / exec / compile, JavaScript eval /
Function() / setTimeout(string), Ruby eval / instance_eval /
class_eval, Java ScriptEngine, PHP eval / assert($str), .NET
Activator.CreateInstance / Reflection.Emit with dynamic input.
Use when: pre-commit gate on any application that parses
user-uploaded code (rule engines, formula evaluators,
plugin systems), or post-bug-report when "we run user-supplied
expressions."
Threshold: any call to eval / exec / Function / similar where the
argument is not a string literal.
Trigger with: "scan eval", "find dynamic exec", "audit eval calls",
"code injection patterns".
|
| allowed-tools | ["Read","Bash(python3:*)","Glob","Grep"] |
| disallowed-tools | ["Bash(rm:*)","Bash(curl:*)"] |
| version | 3.30.0 |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| license | MIT |
| compatibility | Designed for Claude Code |
| tags | ["security","static-analysis","code-injection","pentest"] |
Detecting eval / exec Usage
Overview
Dynamic-code-execution APIs (CWE-95 Eval Injection) let an
application interpret a string as code at runtime. If the string
contains anything user-controllable, the application has handed
the attacker arbitrary code execution.
The defensive posture: don't use these APIs. The exceptions are
narrow: rule engines, formula evaluators (spreadsheet = formulas),
plugin systems with explicit sandboxing. For everything else,
there's almost always a safer alternative.
When the skill produces findings
| Finding | Severity | Threshold | Affected control |
|---|
Python eval(...) with non-literal | CRITICAL | argument contains var ref | CWE-95 |
Python exec(...) with non-literal | CRITICAL | argument contains var ref | CWE-95 |
Python compile(...) with non-literal | HIGH | source string contains var | CWE-95 |
Python __import__(var) | HIGH | dynamic module loading | CWE-95 |
JS eval(...) | CRITICAL | any | CWE-95 |
JS new Function(str) | CRITICAL | any non-literal | CWE-95 |
JS setTimeout/setInterval(string) | HIGH | string instead of function | CWE-95 |
Ruby eval(...)/instance_eval(...)/class_eval(...) | CRITICAL | non-literal | CWE-95 |
PHP eval(...) | CRITICAL | always | CWE-95 |
PHP assert($str) | CRITICAL | (legacy code-eval form) | CWE-95 |
PHP create_function |