T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Remote Package Replacement Without an Independent Trust Root<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1019, 1542-1544`; related disclosure in `SKILL.md:178-183` **Vulnerability Type**: Silent retrieval and installation of remotely controlled executable content **Risk Level**: High ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_update(discovery, get_bytes=get_bytes) _apply_up ...[truncated 2869 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic installation by default and require explicit, informed user approval before replacing package files. 2. Embed an offline publisher public key in the audited client and require a cryptographic signature over the release manifest. 3. Keep the signing key operationally separate from the discovery and CDN infrastructure. 4. Bind the signature to the package slug, version, channel, locale, complete file list, sizes, and hashes. 5. Display the proposed version, verified signer identity, changed executable files, and rollback information before installation. 6. Consider limiting automatic updates to non-executable data. Require additional approval for changes to `scripts/`, `SKILL.md`, or the updater itself. 7. Preserve the existing fixed-domain, redirect refusal, archive validation, ownership checks, locking, and rollback controls as defense-in-depth. ]]>
