T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:178- Finding
Remote Model Code Is Executed Without a Pinned, Vetted Revision
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s local code-search purpose is coherent, but it asks users to run unpinned external code and an executable remote model while indexing sensitive repository content.
Install only if you are comfortable running this third-party MCP server with access to the repositories you index. For sensitive code, pin the package and model to reviewed versions, run it with repository-scoped filesystem access, keep SSE bound to localhost, add `code_memory.db*` to `.gitignore`, and avoid indexing unignored secrets.
SKILL.md:178Remote Model Code Is Executed Without a Pinned, Vetted Revision
SKILL.md:35Unpinned Third-Party Package Installation Creates a Supply-Chain Execution Risk
SKILL.md:125Sensitive Repository Content May Be Persisted in an Accidentally Shareable Database
The skill metadata installs and launches the MCP server via uvx code-memory without pinning an exact package version or immutable artifact. Because uvx resolves the latest available package at runtime, a future upstream compromise, typosquat, or malicious update could cause arbitrary code execution on the host when the skill is installed or started.
The recommended command uvx code-memory fetches and executes an unpinned package version, creating a supply-chain risk window between review time and execution time. In this skill context, the installed tool is a local MCP server with filesystem access to repositories, so a malicious upstream release could run arbitrary code and access sensitive source code or secrets.
The MCP configuration again references uvx code-memory without version pinning, so routine use of the skill may execute whatever package version is current rather than the reviewed one. This is especially risky because the skill is intended for coding workflows in local Git repositories, giving the server access to potentially proprietary codebases and indexed sensitive content.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
permit persons to whom the Software is furnished to do so.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
No suspicious patterns detected.