T09 · Insecure Skill Coding Practices
- Location
reference/workflow.md:164- Finding
TLS Certificate Verification Is Explicitly Disabled
- Content
View full analysis
``` ### Technical Analysis Setting `NODE_TLS_REJECT_UNAUTHORIZED=0` disables TLS certificate validation for the Node.js process. The client can consequently accept expired, self-signed, incorrectly scoped, or attacker-controlled certificates. The instruction specifically recommends this fallback after certificate verification fails. A verification failure can itself indicate interception or endpoint impersonation, making retrying without validation especially dangerous. FlyAI search requests may include travel dates, locations, budgets, family requirements, and other user preferences. Search responses also contain booking and image URLs that the Skill instructs the agent to display. ### Attack Path 1. A user invokes a FlyAI search through the Skill. 2. An attacker controlling the network, DNS resolution, proxy, or gateway causes TLS verification to fail. 3. Following the documented workflow, the agent retries with `NODE_TLS_REJECT_UNAUTHORIZED=0`. 4. The attacker presents an untrusted certificate that the client now accepts. 5. The attacker intercepts travel-profile data or modifies the FlyAI response. 6. The modified response can contain falsified prices, misleading recommendations, or attacker-controlled booking URLs. 7. The agent displays those URLs to the user as actionable booking links. ### Impact Assessment An attacker in a network interception position may obtain the confidentiality and integrity privileges associated with the FlyAI connection. This includes reading submitted travel criteria and modifying returned results. The impact is scoped to traffic and data handled by the affected Node.js process, but it can lead to phishing, fraudulent booking redirection, disclosure ...[truncated 76 chars]- Remediation
View remediation
