T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Default Silent Updates Permit Remote Replacement of Executable Skill Code<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1021` **Additional Locations**: `scripts/mcp_client.py:31-32, 334-357, 469-491, 801-920`; `SKILL.md:222-234` **Vulnerability Type**: Remote payload retrieval and execution without independent publisher authentication **Risk Level**: High ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_ ...[truncated 2889 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable silent automatic replacement by default and require explicit user approval before installing a new version. 2. Sign each release manifest with a dedicated offline package-signing key. 3. Embed or securely provision the corresponding public key in the reviewed client and reject unsigned or incorrectly signed releases. 4. Bind the signature to the package slug, channel, locale, version, complete file list, file hashes, and archive hash. 5. Consider a transparency log or reproducible-build metadata so unauthorized publication can be detected. 6. Keep the existing path, downgrade, archive, size, lock, rollback, and ownership checks as defense-in-depth. 7. Surface update success and the installed version to the user instead of performing replacement silently. ]]>
