T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent Automatic Updates Permit Remote Replacement of Executable Skill Code<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:31-32, 969-1018, 1543` **Vulnerability Type**: Remote payload retrieval and execution **Risk Level**: High ### Vulnerable Code ```python PACKAGE_DISCOVERY_URL = "https://beatra.ai/skills/tiktok-comment-reply-voice/channels/clawhub/install.json" PACKAGE_CDN_BASE_TEMPLATE = "https://cdn.beatra.ai/agent-packages/tiktok-comment-reply-voice/channels/clawhub/v{version}" ``` ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_b ...[truncated 3386 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic updates by default and require explicit, informed approval before replacing executable files. 2. Sign each release manifest with a dedicated offline release-signing key. 3. Embed or securely provision the corresponding public verification key in the reviewed package. 4. Verify the signature before trusting version numbers, archive hashes, file hashes, or replacement instructions. 5. Keep rollback, archive path validation, file-count limits, size limits, and atomic replacement controls; these remain useful defense-in-depth. 6. Display the proposed version, source, signing identity, and changed executable files before installation. 7. Consider separating update checking from update installation so normal MCP operations never alter local executable code. 8. Log update success and failure without including credentials or user content. 9. Provide administrators with a policy mechanism to pin an approved version or disable all network-based package replacement. ]]>
