Security Measures for Graph Data Stored in codebase-memory-mcp: 7 Defensive Layers Explained

The codebase-memory-mcp repository implements seven distinct security layers—from build-time auditing to SQLite authorization callbacks—to protect embedded graph data from unauthorized access, injection attacks, and supply-chain tampering.

The codebase-memory-mcp project by DeusData persists project intelligence in an embedded SQLite database that powers its MCP (Model Context Protocol) server. Understanding the specific security measures for the graph data stored is essential for developers auditing the attack surface or deploying the tool in security-conscious environments. This analysis examines the precise defensive mechanisms implemented in the source code, ranging from low-level C protections to release-time verification workflows.

Build-Time Audit Suite (8 Layers)

Before any code ships, the repository runs a comprehensive build-time audit suite that prevents dangerous calls, accidental secrets, or malicious binaries from entering the supply chain. According to SECURITY.md (lines 100-111), this suite includes static allow-list validation, string-audit scanning, network-egress monitoring via strace, install-output validation, smoke-test hardening, UI auditing, MCP robustness fuzzing, and vendored-dependency integrity checks.

The audit specifically references scripts/security-allowlist.txt to verify that only permitted dangerous calls exist, while scripts/security-fuzz.sh runs adversarial JSON-RPC payload fuzzing against the MCP server to uncover edge-case vulnerabilities before release.

Release Verification and Supply Chain Integrity

At release time, the project guarantees binary authenticity through multiple attestation mechanisms documented in SECURITY.md (lines 121-131). The pipeline generates SLSA provenance attestations, signs artifacts with Sigstore cosign, produces CycloneDX SBOMs, and publishes SHA-256 checksums. Each binary undergoes VirusTotal scanning and OpenSSF Scorecard evaluation to detect tampering or known vulnerabilities.

When users run the update command, the tool verifies downloaded artifacts against the SHA-256 hashes published in checksums.txt (lines 141-142), aborting immediately on mismatch to prevent supply-chain attacks.

Runtime Database Protection

Once the server is running, four distinct runtime protections guard the SQLite graph database from injection and unauthorized access.

SQL Injection Prevention via SQLite Authorizer

To block SQL injection attacks that could attach arbitrary files or modify the database schema, the server registers a custom authorizer callback in internal/cbm/sqlite.c. This callback explicitly denies ATTACH and DETACH operations while allowing legitimate queries.

/* internal/cbm/sqlite.c */
int cbm_sqlite_authorizer(void *unused,
                          int action_code, const char *arg1,
                          const char *arg2, const char *db_name,
                          const char *trigger_name) {
    if (action_code == SQLITE_ATTACH || action_code == SQLITE_DETACH) {
        return SQLITE_DENY;   /* block ATTACH/DETACH */
    }
    return SQLITE_OK;
}

/* During database initialization */
sqlite3_set_authorizer(db, cbm_sqlite_authorizer, NULL);

This mechanism prevents an attacker from using SQL statements to create new database files or access external SQLite databases outside the designated path.

Path Containment and Directory Traversal Protection

Every file-read request undergoes strict path containment checks in internal/cbm/mcp.c to ensure the server only accesses files within the configured project root. The implementation uses realpath() resolution to defeat symbolic link tricks and ../ traversal attempts.

/* internal/cbm/mcp.c */
static bool is_path_inside_root(const char *root, const char *path) {
    char real_root[PATH_MAX];
    char real_path[PATH_MAX];
    realpath(root, real_root);
    realpath(path, real_path);
    return strncmp(real_path, real_root, strlen(real_root)) == 0;
}

If this function returns false, the MCP tool rejects the request immediately, preventing unauthorized reads of system files or other projects' data.

Shell Injection Protection

When the server must execute shell commands, it validates all arguments through cbm_validate_shell_arg() defined in internal/cbm/util.c. This function strips shell metacharacters before any popen() or system() invocation.

/* internal/cbm/util.c */
bool cbm_validate_shell_arg(const char *arg) {
    const char *bad = "`$&|;<>\"'\\*?~()[]{}";
    return strcspn(arg, bad) == strlen(arg);
}

/* Safe execution wrapper */
if (cbm_validate_shell_arg(user_input)) {
    system(user_input);
}

By rejecting strings containing dangerous characters, this measure prevents command injection that could otherwise exfiltrate the graph database or compromise the host system.

CORS Locked to Localhost

The Graph UI HTTP server enforces a strict localhost-only CORS policy in graph-ui/src/server.ts to prevent remote web pages from accessing the graph data through cross-origin requests.

/* graph-ui/src/server.ts */
app.use((req, res, next) => {
  const origin = req.headers.origin;
  if (origin && origin !== "http://localhost") {
    res.setHeader("Access-Control-Allow-Origin", "http://localhost");
    return res.status(403).end("CORS policy: only localhost allowed");
  }
  next();
});

This ensures that even if the server port is exposed to the network, only local browser tabs can query the graph API endpoints.

Summary

The codebase-memory-mcp project protects its SQLite graph database through a defense-in-depth strategy:

  • Build-time hardening prevents vulnerable code from reaching releases via an 8-layer audit suite.
  • Supply-chain verification guarantees binary integrity through SLSA provenance, cosign signatures, and SHA-256 checksum validation.
  • SQL authorization callbacks explicitly deny ATTACH and DETACH operations to prevent database pivoting.
  • Path containment uses canonical path resolution to enforce project-root boundaries.
  • Shell sanitization blocks metacharacters before process execution.
  • CORS restrictions limit UI access to localhost origins only.

Frequently Asked Questions

How does codebase-memory-mcp prevent SQL injection attacks on the graph database?

The server registers a custom SQLite authorizer callback in internal/cbm/sqlite.c that intercepts action codes before execution. This callback returns SQLITE_DENY for any ATTACH or DETACH operation, preventing SQL statements from opening external database files or modifying the connection schema. Legitimate queries proceed normally while malicious injection attempts are blocked at the database engine level.

What prevents the MCP server from reading files outside the project directory?

Path containment is enforced in internal/cbm/mcp.c through the is_path_inside_root() function, which resolves both the project root and requested path using realpath(). If the resolved path does not start with the root directory prefix, the request is rejected. This prevents directory traversal attacks using ../ sequences or symbolic link exploitation.

How is the integrity of released binaries verified?

The release pipeline generates SLSA provenance attestations and signs binaries with Sigstore cosign. Additionally, the update command computes SHA-256 hashes of downloaded artifacts and validates them against checksums.txt before installation. If the checksums do not match exactly, the update aborts to prevent supply-chain tampering.

Can remote websites access the graph data through the UI server?

No. The Graph UI server in graph-ui/src/server.ts implements a strict CORS policy that checks the Origin header on every request. Any origin other than http://localhost receives a 403 Forbidden response. This ensures that even if the server binds to a network-accessible interface, remote web pages cannot access the graph API via cross-origin requests.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →