T03 · Remote Payload Retrieval and Execution
- Location
python/keep/client.py:80- Finding
Mutable Remote Server Artifacts Are Downloaded and Executed
- Content
View full analysis
bool: ``` ```python result = subprocess.run( [ "docker", "run", "-d", "--name", f"keep-server-{port}", "-p", f"{port}:9009", docker_image, ], capture_output=True, text=True, timeout=60, ) ``` ```python result = subprocess.run( ["go", "install", "github.com/clcrawford-dev/keep-server@latest"], capture_output=True, text=True, timeout=120, ) ``` ```python if go_bin: subprocess.Popen( [str(go_bin)], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, start_new_session=True, ) ``` The same capability is exposed directly to agents through `keep_ensure_server()` in `python/keep/mcp/server.py:145-176`. ### Technical Analysis The bootstrap function downloads and executes server software identified by mutable `latest` references. Neither the Docker image nor the Go module is pinned to an immutable digest or version. No checksum, signature, provenance attestation, or trusted-key verification is performed before execution. Consequently, the effective code executed by an already-reviewed Skill can change without any change to this repository. Compromise of the upstream repository, container registry, release pipeline, or publisher credentials could turn an otherwise legitimate bootstrap operation into arbitrary code execution. The Docker path executes the downloaded image through a local Docker daemon. In many environments, Docker access is effectively equivalent to powerful host access. The Go fallback installs a binary into the user's Go binary directory and launches it ...[truncated 1146 chars]- Remediation
View remediation
" ``` 2. Replace `@latest` with an audited, explicit Go module version. 3. Verify release signatures or provenance attestations before execution. 4. Maintain an allowlist of trusted image registries, module paths, versions, and digests. 5. Require explicit user confirmation before any download, installation, or process launch. Agent invocation alone should not authorize software installation. 6. Separate availability checking from installation: - `check_server()` should only inspect connectivity. - `install_server()` should be an explicit administrative operation. 7. Run the server with reduced privileges, a read-only filesystem, dropped Linux capabilities, resource limits, and restricted networking. 8. Return the exact artifact version and digest used so operators can audit the resulting environment. ]]>
