T09 · Insecure Skill Coding Practices
- Location
scripts/workflow.py:73- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/workflow.py:73-109
Vulnerability Type: Improper certificate validation
Risk Level: HighVulnerable Code
python try: ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE req = Request(url, headers=headers, method=method) # Handle request body if 'body' in config: req.data = interpolate(config['body'], context).encode() with urlopen(req, timeout=30, context=ctx) as resp: body = resp.read().decode('utf-8', errors='ignore') try: return json.loads(body) except: return {'raw': body} except URLError as e: return {'error': str(e)}python url = f'https://api.telegram.org/bot{token}/sendMessage' data = {'chat_id': chat_id, 'text': message} ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE req = Request(url, data=json.dumps(data).encode(), headers={'Content-Type': 'application/json'})Technical Analysis
The runner creates a default TLS context but then explicitly disables both certificate verification and hostname checking. This affects generic HTTP actions and Telegram requests.
As a result, the client will accept an expired, self-signed, forged, or otherwise untrusted certificate. HTTPS therefore does not provide reliable server authentication. An attacker able to intercept network traffic can impersonate an API endpoint, inspect request contents, and alter responses.
The Telegram bot token is included in the request URL. Once the attacker terminates the forged TLS connection, that request path and the accompanying message become visible.
Attack Path
- A workflow sends an HTTPS request containing an authorization header, body data, or Telegram bot token.
- An attacker obtains an on-pa ...[truncated 799 chars]
- Remediation
View remediation
Remediation Suggestions
- Retain the secure settings supplied by
ssl.create_default_context(). - Remove both
ctx.check_hostname = Falseandctx.verify_mode = ssl.CERT_NONE. - Use the operating system's trusted CA store by default.
- If private certificate authorities must be supported, accept an explicit CA bundle and load it through
SSLContext.load_verify_locations(). - Do not add a general-purpose option for disabling TLS verification.
- Add automated tests confirming that self-signed, expired, and hostname-mismatched certificates are rejected.
- Consider using the maintained
requestsclient with certificate verification enabled, while still enforcing timeouts and destination restrictions.
- Retain the secure settings supplied by
