T09 · Insecure Skill Coding Practices
- Location
SKILL.md:362- Finding
Hardcoded Root SSH Credential
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 362
Vulnerability Type: Hardcoded privileged credential
Risk Level: HighVulnerable Snippet
markdown - **Server**: ascend-server-01:22 (root/Hhuawei@smb)Technical Analysis
The Skill embeds a plaintext SSH username and password for a root account in distributable documentation. This exposes the credential to every user or process that can read the Skill package.
The project’s documented workflow repeatedly connects to
ascend-server-01asroot, including commands inreferences/verification-method.mdandreferences/troubleshooting.md. If the host is reachable and password authentication is enabled, the exposed credential may permit direct privileged access without an additional authorization boundary.No evidence indicates that the Skill itself transmits this credential to an unrelated party or uses it as part of a covert attack. This is therefore a vulnerable secret-management practice rather than confirmed credential theft or malicious behavior.
Attack Path
- An unauthorized party obtains or reads the distributed Skill package.
- The party extracts the hostname, SSH port, root username, and plaintext password from
SKILL.md. - The party establishes network access to
ascend-server-01:22. - If SSH password authentication remains enabled and the credential is valid, the party authenticates as
root. - The resulting root session can be used to inspect or modify the server, its containers, model files, NPU workloads, and locally accessible secrets.
Successful exploitation depends on the documented server being reachable and accepting the exposed credential.
Impact Assessment
Successful authentication grants root-level administrative privileges on the target server. The attacker could read or alter model and profiling data, modify or stop containers and NPU workloads, access locally stored credentials, install software, or disrupt migration operatio ...[truncated 108 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the hostname/password combination from all tracked files and repository history.
- Rotate the exposed password immediately; removal from the current file does not invalidate previously distributed copies.
- Disable direct root SSH login and password-based SSH authentication where operationally possible.
- Provision individual, least-privilege administrative accounts using managed SSH keys or short-lived certificates.
- Store required secrets in an approved secret manager or deployment-time environment rather than Skill documentation.
- Replace the documentation value with a nonfunctional placeholder, such as:
markdown - **Server**: `<user-provided-host>:<port>` (credentials supplied through an approved secret manager)- Review authentication logs for use of the exposed root credential and investigate any unauthorized access.
- Add secret scanning to development and release workflows to prevent credentials from being committed again.
