T03 · Remote Payload Retrieval and Execution
Error
- Location
- scripts/mcp_client.py:969
- Finding
- Silent unsigned remote updates can replace executable Skill code<![CDATA[ ## Vulnerability Details **File Location**: `scripts/mcp_client.py:969-1019`, `scripts/mcp_client.py:1542-1544` **Vulnerability Type**: Silent remote code replacement without an independent signature trust root **Risk Level**: High ### Vulnerable Code ```python def maybe_auto_update( *, state_dir: Path | None = None, install_root: Path | None = None, get_bytes: GetBytes = _default_get_bytes, now: float | None = None, ) -> bool: """Best-effort silent update. Never block the requested MCP command.""" resolved_state = state_dir or Path.home() / ".beatra" try: resolved_root = (install_root or _current_install_root()).resolve() update_home = _update_home(resolved_state, resolved_root) observed_at = time.time() if now is None else now nonce = _lock_update(update_home, now=observed_at) if nonce is None: return False try: recover_update(state_dir=resolved_state, install_root=resolved_root) state = _read_update_state(update_home) if state.get("auto_update", True) is False: return False last_checked = state.get("last_checked_at") if ( isinstance(last_checked, (int, float)) and observed_at - float(last_checked) < UPDATE_CHECK_MAX_AGE_SECONDS ): return False state["last_checked_at"] = observed_at _write_private_json(update_home / "state.json", state) checked = check_update(get_bytes=get_bytes) if not checked["update_available"]: return False _ensure_owned_baseline( install_root=resolved_root, update_home=update_home, get_bytes=get_bytes, ) discovery = checked["discovery"] manifest, new_files = download_update(discovery, get_bytes=get_bytes) _apply_update( ...[truncated 2532 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. Disable automatic updates by default and require explicit, informed user approval before replacing package files. 2. Sign release manifests with an offline or otherwise independently protected signing key. 3. Embed or securely provision the corresponding public key in the reviewed package and verify the signature before trusting any version, URL, checksum, or file list. 4. Bind the signature to the package name, channel, locale, version, archive digest, manifest contents, and release timestamp. 5. Implement signing-key rotation through a separately authenticated process. 6. Display the current and proposed versions, affected executable files, and publisher identity before installation. 7. Preserve the existing archive validation, path restrictions, ownership checks, transactional replacement, and rollback protections as defense-in-depth. ]]>
