T09 · Insecure Skill Coding Practices
- Location
scripts/aggregator.py:34- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it fetches feeds insecurely and can produce unsafe HTML output, so it should be reviewed before installation.
Install only if you are comfortable reviewing or fixing the helper first. Avoid using HTML output for untrusted feeds, do not run it against feed lists from untrusted sources, and prefer a version that keeps TLS verification enabled and validates feed URLs before fetching.
scripts/aggregator.py:34TLS Certificate and Hostname Verification Disabled
scripts/aggregator.py:38Unrestricted Feed URLs Permit Server-Side Request Forgery
scripts/aggregator.py:142Unescaped Feed Fields Allow Script and Markup Injection in HTML Digests
TLS verification is intentionally disabled with no user warning or opt-in, so users may believe feeds are being fetched securely when they are not. This permits interception or substitution of feed data over HTTPS, enabling content poisoning, misleading digests, and potentially unsafe links in generated output.
The skill advertises behavior that involves both network access and writing files, but it does not declare any explicit tool scope or permissions boundary. That makes the capability surface implicit rather than reviewable, increasing the chance an agent invokes the skill in contexts where network fetching or local file writes were not expected by the user.
The description is broad enough to trigger on generic monitoring, tracking, digest, or newsletter requests, which can cause the skill to activate outside a narrowly scoped RSS/Atom use case. Over-broad routing increases the chance of unnecessary network access, content collection, and file generation in situations where a more constrained skill or direct user confirmation would be safer.
The code explicitly disables TLS hostname and certificate verification before fetching arbitrary feed URLs, which allows a man-in-the-middle attacker to spoof HTTPS feeds and inject untrusted content. In an RSS aggregator, the fetched content is the primary input to downstream processing and output, so losing transport authenticity directly undermines the integrity of all aggregated results.
The examples repeatedly write fetched and aggregated content to user-specified files and temporary paths without warning about overwriting existing files, retaining remote content locally, or exposing sensitive feed data through predictable locations like /tmp. In isolation this is a lower-severity issue, but in an automation context it can lead to unintended data persistence or clobbering of existing files.
The script writes aggregated remote content to a user-specified file path, but provides no prior disclosure in comments, docstrings, or argument help that local files will be created or overwritten. The post-write "Saved to" message confirms completion, but it does not warn users in advance about the file-write behavior.
No suspicious patterns detected.