T09 · Insecure Skill Coding Practices
- Location
SKILL.md:19- Finding
Plaintext SSH Credentials Stored in Deployment Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19 and 61–78
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: HighVulnerable code snippets:
markdown | ssh_password | SSH密码 | 是 | Password |markdown 根据输入参数生成 `config.yaml`,包含: - 节点配置(IP、端口、用户、密码、角色) - VIP配置 - NFS配置 - 容器运行时配置 - Kubernetes版本 - 数据库配置 - 网络配置(calico ipip/bgp) - BOC Portal组件配置markdown ### 3. 上传配置文件到部署机 将生成的 config.yaml 上传到部署机的 `/root/config.yaml`Technical Analysis
The workflow requires an SSH password, embeds node passwords in a generated
config.yaml, and uploads that file to the persistent path/root/config.yaml. It does not require restrictive file permissions, secret redaction, an authenticated encrypted transfer mechanism, ephemeral storage, or deletion after deployment.Consequently, a reusable infrastructure credential may remain in plaintext on both the system generating the configuration and the deployment server. Backups, diagnostic archives, accidental disclosure, overly broad file permissions, or a privileged local process could expose it. The risk is amplified when the supplied account is
root, as shown in the documented examples.Attack Path
- An operator supplies the required SSH username and password to the Skill.
- The Skill generates
config.yamlwith the password included in node configuration. - The generated file is stored locally and uploaded as
/root/config.yaml. - The file remains available without a documented permission-hardening or cleanup procedure.
- An attacker with access to the host, a backup, a support archive, or another unintended copy reads the plaintext credential.
- The attacker uses the credential to authenticate to deployment or cluster nodes.
- If the credential belongs to
root, the attacker obtains administrative control of affected systems and can compromise the BOC/Kubernetes environment.
...[truncated 483 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace password authentication with SSH public-key authentication, an SSH agent, short-lived certificates, or a managed secrets service.
- Do not serialize reusable credentials into
config.yaml. Pass secrets through a protected runtime channel or reference secrets by identifier. - If the deployment software strictly requires a password-bearing file:
- Create it atomically with mode
0600. - Store it only in a protected, non-shared location.
- Transfer it exclusively over an authenticated encrypted protocol.
- Prevent its contents from appearing in command output, logs, status responses, and exception messages.
- Securely remove local and remote copies immediately after deployment.
- Create it atomically with mode
- Use a dedicated least-privilege deployment account rather than
rootwherever the platform supports it. - Rotate any credential that may already have been stored through this workflow.
- Document retention, cleanup, redaction, and file-permission requirements directly in the Skill instructions.
