This connector lets an AI assistant operate a MEGA account through MEGAcmd. This page says what it defends against, what it does not, and the rules the code keeps. Security reviews are judged against it.
An assistant that has been misled. Text the assistant reads — file names, file contents, web pages, messages — can carry instructions written by someone else. The connector assumes any tool call may come from such instructions, and that the user approves actions by reading the confirmation preview their app shows.
- Software already running on the user's computer (malware, another app with the user's permissions, an administrator). It can read MEGAcmd's session store directly, replace installed binaries, or run its own MEGAcmd, without going through this connector.
- Defects in MEGAcmd or the MEGA SDK themselves.
- The user's own deliberate actions, including approving a preview, or setting a tool to "always allow" in their app (which removes the approval step).
- Login never passes through the assistant. No tool takes the account password or returns session or key material.
- The session store is never read, written, uploaded, downloaded into, copied,
moved, shared or published — locally (
~/.megaCmdand its other locations, in any spelling of the path) or as a copy in the cloud (a.megaCmdfolder, a wildcard that could match one, or a folder that contains one). - What runs is what was previewed. Every argument that changes a confirmed
command is shown in its preview and bound into its confirmation token; every
target is listed (at most 200 per confirmation); MEGAcmd reads back exactly the
words that were sent (
src/argv.ts), so no value turns into an option. - Transfers never write into the directories the connector depends on: the MEGAcmd program and cache directories, the plugin's data directory (which holds the file-reading choice) and the macOS login helper — whether the destination is inside one of them or above it.
- File contents reach the assistant only after the user agreed, through the
app's settings or the confirm-gated
mega_file_reading. Turning reading off takes effect for every running server process sharing the plugin's data folder. - Third-party email addresses are shown only after the user agreed (the "Expose contact tools" setting, or a confirmation): contact lists, share recipients, and the people who shared folders with the user.
Rules 2-4 are enforced once more for every MEGAcmd call, whatever tool built it
(src/invocation.ts), on top of each tool's own checks.
- The two-call confirmation is a protocol between the connector and the app. It guarantees that a preview exists and matches what runs; it cannot prove that a person read it. That is the app's approval prompt.
- Signature checks of the MEGAcmd binaries happen before the first command of a process; a binary replaced afterwards by other software is out of scope (above).
- On Windows, only
MEGAclient.exeandMEGAcmdServer.exeare signature-checked, not the DLLs next to them.
Please report vulnerabilities to MEGA through https://mega.io/contact.