T09 · Insecure Skill Coding Practices
- Location
scripts/gh_tool.py:24- Finding
GitHub Token Exposure Due to Disabled TLS Certificate Validation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gh_tool.py, lines 24–26; the insecure context is used at line 40
Vulnerability Type: Improper TLS certificate and hostname validation
Risk Level: HighVulnerable Code:
python ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONEThe resulting context is used for authenticated requests:
python headers = { 'Authorization': f'token {token}', 'Accept': 'application/vnd.github.v3+json', 'User-Agent': 'GitHub-Automation/1.0' } req = urllib.request.Request(url, headers=headers, method=method, data=data) try: with urllib.request.urlopen(req, timeout=30, context=ctx) as response: return json.loads(response.read().decode('utf-8'))Technical Analysis
The script explicitly disables both certificate-chain verification and hostname validation. Consequently, it will accept an arbitrary certificate rather than verifying that the remote peer is genuinely
api.github.com.Every API request includes the
GITHUB_TOKENin itsAuthorizationheader. Although sending that token to GitHub is necessary for the declared automation features, using an unverified TLS connection makes the credential vulnerable to interception. An active network attacker can impersonate GitHub, receive the authorization header and request content, and return forged API responses.Attack Path
- A user invokes the skill with
GITHUB_TOKENconfigured. - An attacker obtains an active network interception position, such as control of an untrusted access point, compromised proxy, or manipulated network route.
- The attacker intercepts the connection intended for
api.github.comand presents an attacker-controlled TLS certificate. - Because hostname and certificate verification are disabled, the script accepts the certificate.
- The script transmits the
Authorization: token ...header ...[truncated 867 chars]
- A user invokes the skill with
- Remediation
View remediation
Remediation Suggestions
- Remove the assignments to
ctx.check_hostnameandctx.verify_mode. - Use Python's default verified TLS behavior:
python ctx = ssl.create_default_context() with urllib.request.urlopen(req, timeout=30, context=ctx) as response: return json.loads(response.read().decode('utf-8'))Alternatively, omit the explicit context so
urlopenuses the platform's trusted certificate configuration.- Never add a fallback that retries with certificate verification disabled.
- Fail closed when certificate-chain or hostname validation fails, and provide a concise error without exposing the token.
- Use a fine-grained GitHub token restricted to only the required repositories and operations. Avoid broad classic
reposcope where narrower permissions suffice. - Rotate the configured token if the vulnerable script has been used on an untrusted or potentially intercepted network.
- Add an automated test using an untrusted certificate to verify that authenticated requests are rejected.
- Remove the assignments to
