T03 · Remote Payload Retrieval and Execution
- Location
reasonix.toml:28- Finding
Unnecessary Network Egress and Automatic Retrieval of an Unpinned Runtime
- Content
View full analysis
Vulnerability Details
File Location:
reasonix.toml, lines 28-59
Vulnerability Type: Excessive privileges and unpinned remote runtime retrieval
Risk Level: MediumVulnerable Configuration
toml [tools] enabled = [] # empty = all built-in tools bash_timeout_seconds = 120 # foreground safety cap; set 0 for no tool-local cap [codegraph] enabled = true # built-in MCP server; off by default for first-run sessions auto_install = true # fetch the runtime when CodeGraph is enabled but missing # path = "" # empty = cache, then PATH, then a bundle beside reasonix [permissions] mode = "ask" allow = ["explore"] [sandbox] bash = "enforce" network = trueThe related executor configuration at line 9 also removes the tool-call round limit:
toml max_steps = 0 # executor tool-call rounds; 0 = no limitTechnical Analysis
The declared Skill functionality consists of local prompt guidance and deterministic text classification. Its executable router reads text from command-line arguments or standard input, classifies it, and returns JSON. It does not require CodeGraph, remote runtime installation, unrestricted built-in tools, or network access.
Nevertheless, the supplied Reasonix configuration:
- Enables the CodeGraph MCP component.
- Automatically fetches its runtime if it is absent.
- Does not pin the runtime to a documented source, version, or integrity hash.
- Enables network egress.
- Makes every built-in tool available because the tool allowlist is empty.
- Permits unlimited executor tool-call rounds.
Automatic retrieval means the effective runtime can differ from the package that was statically reviewed. If the upstream distribution channel, name resolution, download location, or cached artifact is compromised, attacker-controlled runtime content could be introduced after review. Broad tool availability and network access increase ...[truncated 1990 chars]
- Remediation
View remediation
Remediation Suggestions
-
Disable CodeGraph unless the Skill has a documented need for it:
toml [codegraph] enabled = false auto_install = false -
Disable network access for this local-only Skill:
toml [sandbox] network = false -
Replace the empty tool list with an explicit minimal allowlist. If no Reasonix tools are needed by the Skill, deny tool execution rather than interpreting an empty list as all tools.
-
Set a finite executor limit appropriate for text routing:
toml [agent] max_steps = 4 -
If CodeGraph is genuinely required, install it through a controlled deployment process rather than at runtime. Pin the exact version and trusted source, verify a cryptographic checksum or signature, and document the expected artifact.
-
Preserve sandbox enforcement and add explicit deny rules for shell execution, destructive commands, credential locations, and external network tools where supported.
-
Require user approval before any dependency download and record the resolved version and integrity digest in audit logs.
-
