# Security Measures for Graph Data Stored in codebase-memory-mcp: 7 Defensive Layers Explained

> Secure your graph data with codebase-memory-mcp. Discover 7 defensive layers protecting against unauthorized access, injection, and tampering. Learn more!

- Repository: [Martin Vogel/codebase-memory-mcp](https://github.com/DeusData/codebase-memory-mcp)
- Tags: best-practices
- Published: 2026-07-05

---

**The `codebase-memory-mcp` repository implements seven distinct security layers—from build-time auditing to SQLite authorization callbacks—to protect embedded graph data from unauthorized access, injection attacks, and supply-chain tampering.**

The `codebase-memory-mcp` project by DeusData persists project intelligence in an embedded SQLite database that powers its MCP (Model Context Protocol) server. Understanding the specific security measures for the graph data stored is essential for developers auditing the attack surface or deploying the tool in security-conscious environments. This analysis examines the precise defensive mechanisms implemented in the source code, ranging from low-level C protections to release-time verification workflows.

## Build-Time Audit Suite (8 Layers)

Before any code ships, the repository runs a comprehensive build-time audit suite that prevents dangerous calls, accidental secrets, or malicious binaries from entering the supply chain. According to [`SECURITY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/SECURITY.md) (lines 100-111), this suite includes static allow-list validation, string-audit scanning, network-egress monitoring via `strace`, install-output validation, smoke-test hardening, UI auditing, MCP robustness fuzzing, and vendored-dependency integrity checks.

The audit specifically references [`scripts/security-allowlist.txt`](https://github.com/DeusData/codebase-memory-mcp/blob/main/scripts/security-allowlist.txt) to verify that only permitted dangerous calls exist, while [`scripts/security-fuzz.sh`](https://github.com/DeusData/codebase-memory-mcp/blob/main/scripts/security-fuzz.sh) runs adversarial JSON-RPC payload fuzzing against the MCP server to uncover edge-case vulnerabilities before release.

## Release Verification and Supply Chain Integrity

At release time, the project guarantees binary authenticity through multiple attestation mechanisms documented in [`SECURITY.md`](https://github.com/DeusData/codebase-memory-mcp/blob/main/SECURITY.md) (lines 121-131). The pipeline generates SLSA provenance attestations, signs artifacts with Sigstore cosign, produces CycloneDX SBOMs, and publishes SHA-256 checksums. Each binary undergoes VirusTotal scanning and OpenSSF Scorecard evaluation to detect tampering or known vulnerabilities.

When users run the update command, the tool verifies downloaded artifacts against the SHA-256 hashes published in [`checksums.txt`](https://github.com/DeusData/codebase-memory-mcp/blob/main/checksums.txt) (lines 141-142), aborting immediately on mismatch to prevent supply-chain attacks.

## Runtime Database Protection

Once the server is running, four distinct runtime protections guard the SQLite graph database from injection and unauthorized access.

### SQL Injection Prevention via SQLite Authorizer

To block SQL injection attacks that could attach arbitrary files or modify the database schema, the server registers a custom authorizer callback in [`internal/cbm/sqlite.c`](https://github.com/DeusData/codebase-memory-mcp/blob/main/internal/cbm/sqlite.c). This callback explicitly denies `ATTACH` and `DETACH` operations while allowing legitimate queries.

```c
/* internal/cbm/sqlite.c */
int cbm_sqlite_authorizer(void *unused,
                          int action_code, const char *arg1,
                          const char *arg2, const char *db_name,
                          const char *trigger_name) {
    if (action_code == SQLITE_ATTACH || action_code == SQLITE_DETACH) {
        return SQLITE_DENY;   /* block ATTACH/DETACH */
    }
    return SQLITE_OK;
}

/* During database initialization */
sqlite3_set_authorizer(db, cbm_sqlite_authorizer, NULL);

```

This mechanism prevents an attacker from using SQL statements to create new database files or access external SQLite databases outside the designated path.

### Path Containment and Directory Traversal Protection

Every file-read request undergoes strict path containment checks in [`internal/cbm/mcp.c`](https://github.com/DeusData/codebase-memory-mcp/blob/main/internal/cbm/mcp.c) to ensure the server only accesses files within the configured project root. The implementation uses `realpath()` resolution to defeat symbolic link tricks and `../` traversal attempts.

```c
/* internal/cbm/mcp.c */
static bool is_path_inside_root(const char *root, const char *path) {
    char real_root[PATH_MAX];
    char real_path[PATH_MAX];
    realpath(root, real_root);
    realpath(path, real_path);
    return strncmp(real_path, real_root, strlen(real_root)) == 0;
}

```

If this function returns false, the MCP tool rejects the request immediately, preventing unauthorized reads of system files or other projects' data.

### Shell Injection Protection

When the server must execute shell commands, it validates all arguments through `cbm_validate_shell_arg()` defined in [`internal/cbm/util.c`](https://github.com/DeusData/codebase-memory-mcp/blob/main/internal/cbm/util.c). This function strips shell metacharacters before any `popen()` or `system()` invocation.

```c
/* internal/cbm/util.c */
bool cbm_validate_shell_arg(const char *arg) {
    const char *bad = "`$&|;<>\"'\\*?~()[]{}";
    return strcspn(arg, bad) == strlen(arg);
}

/* Safe execution wrapper */
if (cbm_validate_shell_arg(user_input)) {
    system(user_input);
}

```

By rejecting strings containing dangerous characters, this measure prevents command injection that could otherwise exfiltrate the graph database or compromise the host system.

### CORS Locked to Localhost

The Graph UI HTTP server enforces a strict localhost-only CORS policy in [`graph-ui/src/server.ts`](https://github.com/DeusData/codebase-memory-mcp/blob/main/graph-ui/src/server.ts) to prevent remote web pages from accessing the graph data through cross-origin requests.

```javascript
/* graph-ui/src/server.ts */
app.use((req, res, next) => {
  const origin = req.headers.origin;
  if (origin && origin !== "http://localhost") {
    res.setHeader("Access-Control-Allow-Origin", "http://localhost");
    return res.status(403).end("CORS policy: only localhost allowed");
  }
  next();
});

```

This ensures that even if the server port is exposed to the network, only local browser tabs can query the graph API endpoints.

## Summary

The `codebase-memory-mcp` project protects its SQLite graph database through a defense-in-depth strategy:

- **Build-time hardening** prevents vulnerable code from reaching releases via an 8-layer audit suite.
- **Supply-chain verification** guarantees binary integrity through SLSA provenance, cosign signatures, and SHA-256 checksum validation.
- **SQL authorization callbacks** explicitly deny `ATTACH` and `DETACH` operations to prevent database pivoting.
- **Path containment** uses canonical path resolution to enforce project-root boundaries.
- **Shell sanitization** blocks metacharacters before process execution.
- **CORS restrictions** limit UI access to localhost origins only.

## Frequently Asked Questions

### How does codebase-memory-mcp prevent SQL injection attacks on the graph database?

The server registers a custom SQLite authorizer callback in [`internal/cbm/sqlite.c`](https://github.com/DeusData/codebase-memory-mcp/blob/main/internal/cbm/sqlite.c) that intercepts action codes before execution. This callback returns `SQLITE_DENY` for any `ATTACH` or `DETACH` operation, preventing SQL statements from opening external database files or modifying the connection schema. Legitimate queries proceed normally while malicious injection attempts are blocked at the database engine level.

### What prevents the MCP server from reading files outside the project directory?

Path containment is enforced in [`internal/cbm/mcp.c`](https://github.com/DeusData/codebase-memory-mcp/blob/main/internal/cbm/mcp.c) through the `is_path_inside_root()` function, which resolves both the project root and requested path using `realpath()`. If the resolved path does not start with the root directory prefix, the request is rejected. This prevents directory traversal attacks using `../` sequences or symbolic link exploitation.

### How is the integrity of released binaries verified?

The release pipeline generates SLSA provenance attestations and signs binaries with Sigstore cosign. Additionally, the `update` command computes SHA-256 hashes of downloaded artifacts and validates them against [`checksums.txt`](https://github.com/DeusData/codebase-memory-mcp/blob/main/checksums.txt) before installation. If the checksums do not match exactly, the update aborts to prevent supply-chain tampering.

### Can remote websites access the graph data through the UI server?

No. The Graph UI server in [`graph-ui/src/server.ts`](https://github.com/DeusData/codebase-memory-mcp/blob/main/graph-ui/src/server.ts) implements a strict CORS policy that checks the `Origin` header on every request. Any origin other than `http://localhost` receives a 403 Forbidden response. This ensures that even if the server binds to a network-accessible interface, remote web pages cannot access the graph API via cross-origin requests.