charly-mcp-cmd
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill intentionally exposes the entire charly CLI over MCP — including arbitrary command/tool invocation, file read/write (including host bind-mounted project files), secrets/password/GPG operations, and mutating/destructive tools by default — which constitutes a remote code execution / backdoor surface enabling data exfiltration and credential/system compromise if the server is reachable by untrusted parties.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). charly mcp serve auto-fetches a remote repo at runtime — by default cloning github.com/overthinkos/overthink (and via CHARLY_PROJECT_REPO you can point to any repo) — and the cloned project becomes the server's project root (influencing charly.yml, prompt/resources and the MCP-exposed tools that can run builds/commands), so remote repository content fetched at runtime can directly control agent-visible prompts and behavior; flagged URL: github.com/overthinkos/overthink
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). This skill exposes the full charly CLI as remotely-callable MCP tools — including many destructive actions (passwd, service., create/destroy VMs, start/stop services, box.write/box.new., add-rpm, mount/unmount, etc.) and file-write authoring that can modify bind-mounted host project files — so an agent calling the server can create users, change system services, or write privileged files; the presence of a --read-only flag is a mitigant but does not prevent the default/advertised surface from being able to compromise machine state.
Issues (3)
E006
CRITICALMalicious code pattern detected in skill scripts.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata