T09 · Insecure Skill Coding Practices
- Location
scripts/npu_client.py:52- Finding
SSH Host-Key Verification Is Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/npu_client.py, lines 52–59
Vulnerability Type: Improper SSH server authentication
Risk Level: HighVulnerable Code
python self._ssh_client = paramiko.SSHClient() self._ssh_client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) self._ssh_client.connect( hostname=self.ssh_host, port=self.ssh_port, username=self.ssh_user, password=self.ssh_password, timeout=30, look_for_keys=False, allow_agent=False )Technical Analysis
The SSH client applies
paramiko.AutoAddPolicy(), which silently trusts a previously unknown host key. It does not load and enforce a trusted known-hosts entry or require the user to verify the server fingerprint.Remote mode authenticates with the password supplied through the Skill's
--passwordparameter. Consequently, an attacker who can intercept or redirect the connection can present an arbitrary SSH host key and be accepted as the intended NPU server. The subsequent password authentication and administrative command traffic then occur over a cryptographically protected connection to the attacker's server rather than the authorized endpoint.The attacker-controlled point is the SSH endpoint visible to the client. Exploitation requires a network-positioning or redirection capability, such as traffic interception or compromise of the mechanism used to resolve or route to the selected host. Merely supplying normal user-selected connection parameters does not trigger the vulnerability.
Attack Path
- The user invokes the Skill in SSH mode with an authorized target host, username, and password.
- An attacker capable of intercepting or redirecting traffic causes the connection to reach an attacker-controlled SSH server.
- The malicious server presents a host key that is not already trusted by the client.
AutoAddPolicy()accepts the unknown key without fingerprint verification.- The client submits the configured SSH u ...[truncated 659 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
AutoAddPolicywithparamiko.RejectPolicy(). - Load trusted host keys before connecting, for example through
load_system_host_keys()and an application-specific known-hosts file. - Require explicit fingerprint verification and enrollment when connecting to a new host.
- Treat host-key changes as hard failures and show both the expected and received fingerprints through a trusted user interface.
- Do not silently retry a connection in a way that weakens host-key validation.
- Prefer key-based user authentication where practical, while retaining strict server host-key verification regardless of the client authentication method.
- Replace
