Attackers exploit an agent's code-generation or code-execution capability to run unsafe or malicious code, escalate privilege, or compromise the host system directly. In a multi-agent system: A DevOps agent is manipulated into generating an infrastructure script that embeds a hidden command disabling logging before it provisions the requested resource. Prima…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Unexpected RCE and code attacks describe the risk that uncontrolled agent or model output executes unintended code.
The idea comes from application security around remote code execution and unsafe output handling. OWASP applies this risk class to LLM and agentic systems whose output can reach interpreters, shells, or tools.
Output starts as text but can become a command at a system boundary. If unchecked, manipulated output may execute code. Separation, allow-lists, and sandboxes put a gate in front of it.
Text becomes dangerous when an interpreter treats it as a command.
Generated content needs validation.
Sandboxes limit impact.
This pattern helps secure agentic code and tool chains against unexpected execution. It fits executable outputs; least privilege remains necessary.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.