T09 · Insecure Skill Coding Practices
- Location
index.js:18- Finding
Grafana Credentials May Be Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
index.js:18-29; insecure configuration example atSKILL.md:51-58
Vulnerability Type: Transmission of reusable credentials over an unencrypted channel
Risk Level: MediumVulnerable Code
index.js:18-29:js const basicAuth = (user, password) => "Basic " + Buffer.from(`${user}:${password}`).toString("base64"); const grafanaFetch = (url, user, password, path, options = {}) => fetch(`${url}${path}`, { ...options, headers: { Authorization: basicAuth(user, password), "Content-Type": "application/json", ...options.headers, }, });SKILL.md:51-58:json { "plugins": { "entries": { "rpe-grafana": { "enabled": true, "config": { "url": "http://your-grafana:3000", "user": "your-username",Technical Analysis
The plugin builds a reusable HTTP Basic Authentication value from the configured Grafana username and password or API key. Base64 encoding does not provide encryption. The resulting authorization header is attached to every Grafana request.
The configured URL is accepted without validating its scheme, and the documented setup explicitly demonstrates an
http://Grafana endpoint. If that example is followed across a network, the authorization header and Grafana responses are transmitted without transport encryption.Authenticated network access is necessary for the Skill's declared purpose, and the reviewed code sends credentials only to the configured Grafana host. However, permitting plaintext transport is not necessary for normal production operation and exposes credentials beyond the minimum safe boundary.
Attack Path
- An operator configures
GRAFANA_URLor the pluginurlwith anhttp://endpoint, potentially following the supplied documentation. - A user invokes one of the Grafana tools.
grafanaFetchconst ...[truncated 1117 chars]
- An operator configures
- Remediation
View remediation
Remediation Suggestions
- Require Grafana URLs to use the
https:scheme before making any request. - If local development requires plaintext HTTP, permit it only through an explicit opt-in setting and restrict it to loopback addresses such as
localhost,127.0.0.1, or::1. - Replace the
http://your-grafana:3000documentation example with an HTTPS URL and clearly warn that Basic Authentication must not be used over plaintext HTTP. - Recommend a dedicated, least-privilege Grafana service account token with only the dashboard and datasource query permissions required by this Skill.
- Avoid the fallback username of
admin; require explicit credential configuration so users are not encouraged to use an administrative account. - Where appropriate, validate the configured destination against an administrator-controlled allowlist to reduce accidental credential disclosure to an incorrect host.
- Return a clear configuration error without issuing a request when the URL is missing, malformed, or uses an unsafe scheme.
- Require Grafana URLs to use the
