| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Hi @geoffw0 — hope you are well. You reviewed and merged my earlier C++ MMIO PR (#22438); thank you again for that. When you have a moment, I would appreciate a look at this Python follow-up for #22702. It models MCP / FastMCP server handler parameters as RemoteFlowSources in QL (Mcp.qll), mainly so queries that still take RemoteFlowSource directly (e.g. py/xxe, py/xml-bomb, py/nosql-injection) can see MCP tool/prompt/resource args, and so stacked custom decorators on handlers are covered via getADecorator() (similar to Flask routing). There is already open MaD coverage in #22703; this PR is intentionally QL-only and complementary. Library tests are under python/ql/test/library-tests/dataflow/remote-flow-sources/ and pass locally with codeql test run. No rush — happy to adjust based on team preference (QL vs MaD, scope, naming). Thanks for any pointers. |
Sorry, something went wrong.
| */ | ||
|
|
||
| private import python | ||
| private import semmle.python.dataflow.new.DataFlow |
|
Hi, this looks reasonable at a glance (though I was a little surprised to see QL-modelled sources rather than MaD models). In any case I've started the tests and am handing over to another member of the team. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Summary
Fixes #22702.
This PR adds QL framework modeling for Python MCP (Model Context Protocol) and fastmcp server handler parameters as RemoteFlowSources.
Why QL Modeling instead of Models-as-Data (YAML)
Existing open PR #22703 models MCP via Models-as-Data (MaD) YAML (ThreatModelSource of kind remote). However, several legacy Python security queries (such as py/nosql-injection, py/xml-bomb, and py/xxe) query RemoteFlowSource::Range directly and do not consume MaD sources. Additionally, MaD currently misses tool handlers wrapped behind stacked custom decorators.
Modeling via Mcp.qll extending RemoteFlowSource::Range resolves both gaps natively.
What is Modeled
Exclusions
Testing