Contain code an agent generates or is induced to run. Execute in a sandboxed container with least privilege and deny-by-default egress, prefer parameterised APIs over raw shell, and treat any string reaching a subprocess or interpreter as attacker-controlled. Use when adding a code interpreter, shell tool, subprocess call, or eval-style API to an agent. Do NOT use for eval/exec appearing in ordinary application code \u2014 that is `code-safety`.
Installs into .claude/skills of the current project.
Are you the author of Owasp Asi05 Unexpected Code Execution?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/open-coder-ai-owasp-asi05-unexpected-code-execution)
---
name: owasp-asi05-unexpected-code-execution
description: "Contain code an agent generates or is induced to run. Execute in a sandboxed container with least privilege and deny-by-default egress, prefer parameterised APIs over raw shell, and treat any string reaching a subprocess or interpreter as attacker-controlled. Use when adding a code interpreter, shell tool, subprocess call, or eval-style API to an agent. Do NOT use for eval/exec appearing in ordinary application code \u2014 that is `code-safety`."
metadata:
chock.artifact: rule
chock.enforcement: advise
chock.coverage_without_chock: advisory
---
# OWASP ASI05 — Unexpected Code Execution
Contain code an agent generates or is induced to run. Execute in a sandboxed container with least privilege and deny-by-default egress, prefer parameterised APIs over raw shell, and treat any string reaching a subprocess or interpreter as attacker-controlled. Use when adding a code interpreter, shell tool, subprocess call, or eval-style API to an agent. Do NOT use for eval/exec appearing in ordinary application code — that is `code-safety`.
```
run(agent_generated_code): container(least_privilege) + egress(deny_by_default) + filesystem(scoped) + timeout; never(host_execution)
never(pass): untrusted_string -> shell | eval | interpreter | deserializer; prefer(parameterized_api) over(raw_shell); see(agentic-code-security pack exec): mechanises part, the rest stays advisory; see .agents/policies/owasp-asi05-unexpected-code-execution/references/code-execution.md
```
This skill is advisory: the client reading it has no mechanism to enforce it, and this policy stays advisory even when compiled by `chock` -- it ships rule text, not a blocking hook. See https://github.com/open-coder-ai/chock