T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Automatic Updates Permit Post-Audit Code Replacement<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1018`, `scripts/mcp_client.py:1539-1543`; behavior documented in `SKILL.md:138-153` **Vulnerability Type**: Remote payload retrieval and execution through a default-enabled self-updater **Risk Level**: High ### Code Snippet ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_update(discovery, get_bytes=get_byte ...[truncated 3168 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Default `auto_update` to `False` for new installations. 2. Require explicit, informed user confirmation before downloading and applying a release. 3. Sign discovery metadata and release manifests with an offline release key, and pin the corresponding public key in the audited client. 4. Verify signatures independently of TLS and CDN-provided hashes. 5. Display the current version, target version, changed file list, and release identity before replacement. 6. Provide a version-pinning option so security-sensitive installations can remain on an audited release. 7. Separate update checking from update installation; an automatic check must not imply automatic replacement. 8. Consider distributing updates through the host platform's reviewed package mechanism rather than implementing in-process self-modification. ]]>
