{"citation":"QX-L-0004","resolved":true,"appealable":true,"ruleset":"2026.07.2","law":{"id":"QX-L-0004","key":"call_args.malicious","title":"Malicious call argument","text":"A tool call whose arguments contain an unambiguous attack signature must be denied, regardless of whether the tool itself is legitimate.","rationale":"The common real attack is a clean tool driven with a hostile value: a cloud metadata address, a credential file path, a shell injection. Verifying only the tool definition misses this entirely, because the definition is honest and the argument is not.","severity":"prohibition","effect":"deny","branch":"executive","inForceSince":"2026.07.1","status":"active","appealable":true,"mappings":[{"framework":"OWASP-ASI","id":"ASI05","note":"Unexpected Code Execution"}]}}