T09 · Insecure Skill Coding Practices
- Location
scripts/meshmonitor_api.py:8- Finding
Bearer Token Can Be Transmitted Over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/meshmonitor_api.py:8-18; insecure usage is documented inSKILL.md:24andSKILL.md:107-127
Vulnerability Type: Plaintext transmission of authentication credentials
Risk Level: HighVulnerable Code
python def req(url, token=None, method='GET', body=None): headers = {} data = None if token: headers['Authorization'] = f'Bearer {token}' if body is not None: headers['Content-Type'] = 'application/json' data = json.dumps(body).encode('utf-8') r = urllib.request.Request(url, headers=headers, method=method, data=data) with urllib.request.urlopen(r, timeout=30) as resp: return resp.read().decode('utf-8', errors='replace')The documented usage explicitly demonstrates an unencrypted URL:
bash python3 scripts/meshmonitor_api.py --base-url http://HOST:PORT --token 'mm_v1_...' infoTechnical Analysis
The CLI accepts an arbitrary base URL and attaches the user-supplied bearer token to the HTTP
Authorizationheader. It neither requires HTTPS nor warns or requests confirmation when the URL uses plaintext HTTP. The project documentation actively recommends anhttp://example.HTTP provides no confidentiality or server authentication. An attacker capable of observing or modifying traffic between the client and the MeshMonitor server can recover the complete bearer token. Because bearer credentials do not require additional proof of possession, possession of the captured value is sufficient to impersonate the user.
Network communication is necessary for the declared MeshMonitor integration, but permitting sensitive authentication over plaintext transport by default exceeds safe minimum-privilege handling of the credential.
Attack Path
- A user follows the documented example and supplies an
http://MeshMonitor base URL. - The helper adds the MeshMonitor token to the ...[truncated 1012 chars]
- A user follows the documented example and supplies an
- Remediation
View remediation
Remediation Suggestions
- Require
https://for authenticated requests by default. - Reject plaintext HTTP whenever a bearer token is present.
- If local or legacy HTTP support is unavoidable, require an explicit option such as
--allow-insecure-httpand display a prominent credential-exposure warning. - Consider allowing plaintext HTTP only for loopback addresses, while still requiring explicit consent.
- Replace the HTTP examples in
SKILL.mdwith HTTPS examples. - Document certificate validation requirements and avoid recommending disabled TLS verification.
- Test the URL scheme before constructing or sending the authenticated request.
- Require
