T09 · Insecure Skill Coding Practices
- Location
scripts/generate_videos.py:25- Finding
Plaintext FTP Credentials and Unencrypted Media Transport
- Content
View full analysis
``` ### Technical Analysis The implementation uses `ftplib.FTP`, which does not encrypt authentication credentials, control commands, or uploaded files. Consequently, the FTP username and password and all generated images can be observed by an attacker with access to the network path. The documented retrieval URL uses unencrypted HTTP. There is no transport-level protection against interception or modification when the image-generation output is later retrieved for video generation. The implementation also does not verify file integrity after upload, apply access controls through short-lived signed URLs, or remove remote files after use. Environment variables prevent credentials from being hardcoded in source control, but they do not protect those credentials while FTP transmits them over the network. ### Attack Path 1. A user runs the video-generation workflow, causing generated images to be uploaded to the configured server. 2. The script connects to port 21 with standard FTP and transmits the configured username and password without encryption. 3. An attacke ...[truncated 1332 chars]- Remediation
View remediation
