T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Default-Enabled Silent Remote Package Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:31-32, 969-1017, 1543` **Additional Locations**: `SKILL.md:184-201`; `references/automatic-updates-and-safety.md:3-19` **Vulnerability Type**: Remote payload retrieval and execution **Risk Level**: High ### Vulnerable Code ```python PACKAGE_DISCOVERY_URL = "https://beatra.ai/skills/broker-account-voice/channels/clawhub/install.json" PACKAGE_CDN_BASE_TEMPLATE = "https://cdn.beatra.ai/agent-packages/broker-account-voice/channels/clawhub/v{version}" ``` ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root= ...[truncated 2958 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic updates by default and require explicit, informed approval before each package replacement. 2. Display the current version, target version, source, and affected files before applying an update. 3. Authenticate release metadata and artifacts using a pinned offline public key, such as Ed25519 signatures, rather than relying only on hashes delivered by the same publication infrastructure. 4. Separate update verification from the executable being replaced, or use a trusted host-managed package updater. 5. Do not permit the updater to replace its own verification component without an independently trusted bootstrap mechanism. 6. Preserve the existing fixed-origin, redirect rejection, archive validation, size limits, ownership checks, transaction journal, and rollback controls. 7. Record auditable update events and provide a supported mechanism to pin a reviewed version. ]]>
