Skip to content

MCP host hands a locally-spawned stdio server the operator's entire environment

mcp-child-env-inheritance is a high severity check in the ai category, written in shell. Its source is templates/ai/mcp/mcp-child-env-inheritance.sh in cert-x-gen-templates.

Exports uniquely-valued canary credentials (AWS, GitHub, npm, registry, cloud-CLI) into the host’s own environment, then asks the target MCP host to launch a synthetic stdio MCP server whose manifest declares a need for exactly one variable. The spawned child reports the environment it actually received. CONFIRMED when a canary nonce the manifest never declared is visible to the child - the child’s credential blast radius is the whole workstation, not its declared need; REFUTED when the child receives its declared variable and none of the undeclared canaries; SKIP when no stdio-launch surface could be exercised. The oracle is zero-false-positive by construction: every canary value is a nonce minted this run, so a value in the child cannot have arrived any way but inheritance.

Field Value
Id mcp-child-env-inheritance
Severity high
Language shell
Category ai
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 95
CVSS not recorded
Weakness CWE-250
Tags ai, mcp, cli, stdio, environment, credential-inheritance, blast-radius, least-privilege, cwe-250, cwe-522, cwe-668
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info mcp-child-env-inheritance

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.