Back to skill

Security audit

Codegraph Tool

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local code-indexing skill, but its install guidance asks users to run mutable remote or unpinned package code and optionally grants broad MCP auto-allow permissions.

Review the CodeGraph package and installer before use, prefer a pinned version or verified release artifact, avoid curl-to-sh installation, and do not enable Claude auto-allow permissions unless you trust the MCP server and are comfortable letting it read indexed project code without per-call approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:18
Finding

Unreviewed Remote Installer Is Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 18
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install.sh | sh  # No Node required

Technical Analysis

The installation instructions retrieve install.sh from the mutable main branch of a personal GitHub repository and pipe its contents directly into sh. The downloaded script is not included in the audited project, pinned to an immutable commit, checked against a cryptographic digest, or authenticated with a release signature.

Consequently, the code executed by this command can change after the Skill has been reviewed. Piping the response directly to a shell also prevents meaningful inspection before execution. The use of HTTPS protects the network connection under normal conditions but does not protect against repository compromise, publisher-account takeover, or a malicious later update to the referenced branch.

This behavior exceeds the minimum privileges necessary for the declared installation function because the documentation already provides npm-based alternatives; arbitrary mutable shell-script execution is not intrinsically required to install a local code-indexing tool.

Attack Path

  1. An attacker compromises the GitHub repository, maintainer account, or another component controlling the remote installer.
  2. The attacker changes install.sh on the referenced main branch.
  3. A user or automated Agent follows the documented installation command.
  4. curl retrieves the attacker's current script without version or integrity verification.
  5. sh immediately executes the response with the privileges of the invoking user.
  6. The payload can access or alter any resources available to that user.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoki ...[truncated 469 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the direct curl | sh installation method.
  • Prefer a project-local package installation with an exact, audited version recorded in a lockfile.
  • If a standalone installer is necessary, publish it as a versioned release artifact rather than retrieving it from a mutable branch.
  • Pin the artifact to an immutable release or commit and publish a SHA-256 or stronger cryptographic digest.
  • Verify the digest or a trusted release signature before execution.
  • Download the installer to a file first, permit inspection, and execute it only after verification.
  • Ensure the installer operates without elevated privileges and clearly documents every filesystem or configuration change.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned npm Commands Can Execute or Install Future Package Releases

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–19
Vulnerability Type: Insecure dependency installation and execution
Risk Level: Medium

Vulnerable Code:

bash
npx @colbymchenry/codegraph          # Recommended: one-click install + auto-configure Agent
curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install.sh | sh  # No Node required
npm i -g @colbymchenry/codegraph     # npm

The dependency-specific affected commands are:

bash
npx @colbymchenry/codegraph
npm i -g @colbymchenry/codegraph

Technical Analysis

Both npm commands omit an exact package version. Package resolution can therefore select a future release that was not part of this audit. The npx command may download and immediately execute package code, while the global installation command installs the resolved package into the user's configured global npm prefix.

npm packages can execute CLI code and may run lifecycle scripts during installation. If the publisher account or package distribution channel is compromised, or a malicious future version is published under the same package name, following these instructions could execute attacker-controlled code.

No package lockfile, integrity value, reviewed vendored source, or exact audited version is supplied by this documentation. Global installation is also broader than necessary for project-local operation and increases the package's persistence and availability across projects.

Attack Path

  1. An attacker gains control of the package publisher account or otherwise causes a malicious release to be published as the version selected by npm.
  2. A user follows the unpinned npx or global npm installation instruction.
  3. npm resolves and downloads the malicious release.
  4. Package lifecycle scripts or the invoked CLI execute with the invoking user's privileges.
  5. The malicious package accesses user-readable data or modifies fil ...[truncated 677 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the package to an exact reviewed version, for example @colbymchenry/codegraph@X.Y.Z.
  • Prefer a project-local dependency over global installation.
  • Record the exact dependency and integrity metadata in a committed lockfile.
  • Use npm ci in automated environments so dependency resolution follows the lockfile.
  • Review package contents and lifecycle scripts before approving a version.
  • Disable lifecycle scripts during installation where compatible, then explicitly run only required, reviewed setup steps.
  • Establish a controlled upgrade process that reviews and tests each new release before changing the pinned version.
  • Avoid recommending npx execution without an exact version because it combines retrieval and immediate execution.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The documentation instructs users to add ~/.claude/settings.json auto-allow permissions for the CodeGraph MCP tool, which weakens the agent's permission boundary and enables silent execution of codegraph capabilities without per-action approval. If the MCP server is compromised, misconfigured, or abused through prompt injection, these pre-approved permissions can expose repository structure, symbol relationships, and code context from sensitive local projects with reduced user visibility.

Content

Scanner excerpt · references/configuration.md (reported line 42)May include surrounding context.

{ "mcpServers": { "codegraph": { "type": "stdio", "command": "codegraph", "args": ["serve", "--mcp"] } } }

text

`~/.claude/settings.json` (optional auto-allow):
```json
{ "permissions": { "allow": ["mcp__codegraph__codegraph_search","mcp__codegraph__codegraph_explore","mcp__codegraph__codegraph_callers","mcp__codegraph__codegraph_callees","mcp__codegraph__codegraph_impact","mcp__codegraph__codegraph_node","mcp__codegraph__codegraph_status","mcp__codegraph__codegraph_files"] } }

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance says to use this tool for 'almost any question' and positions it as the primary tool, which can cause over-invocation by agents beyond narrowly appropriate contexts. While not direct code execution, broad activation instructions increase the chance an agent will rely on this external capability unnecessarily, expanding attack surface and potentially exposing more repository context than needed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx @colbymchenry/codegraph without a pinned version allows execution of whatever package version is current at install time. If the package is compromised, typo-squatted, or a malicious update is published, users or agents following the skill may execute unreviewed code with local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

curl ... | sh executes a remote script directly from GitHub without pinning to a specific immutable commit or verifying integrity. If the remote content, repository, distribution path, or transport trust is compromised, arbitrary shell commands will run immediately on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

bash
npx @colbymchenry/codegraph          # Recommended: one-click install + auto-configure Agent
curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install.sh | sh  # No Node required
npm i -g @colbymchenry/codegraph     # npm

Static analysis

No suspicious patterns detected.