T09 · Insecure Skill Coding Practices
- Location
scripts/devkit_remote.py:206- Finding
Unauthenticated SSH Connection to the Privileged DevKit Server
- Content
View full analysis
Vulnerability Details
File Location:
scripts/devkit_remote.py, lines 206–211
Vulnerability Type: SSH host-key verification bypass
Risk Level: HighComplete Code Snippet:
python def get_ssh_client(host, user, password, retries=3, delay=10): client = paramiko.SSHClient() client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) last_err = None for attempt in range(1, retries + 1): # ... try: client.connect(host, port=22, username=user, password=password, timeout=15) return client, user, passwordTechnical Analysis
paramiko.AutoAddPolicy()accepts and records any previously unknown SSH host key without validating it through a trusted fingerprint or pre-provisionedknown_hostsentry. Consequently, possession of the expected network address is treated as sufficient proof of server identity.This function is the common connection path for operations that check the server, upload scripts, install DevKit, run scans, and download reports. The connection uses the privileged
DEVKIT_ECS_USERandDEVKIT_ECS_PASSWORDcredentials. Although the project redacts the password from output, output redaction does not protect it from a server impersonating the intended SSH endpoint during password authentication.Attack Path
- The user or Agent invokes an operation such as
check,upload,install,scan,download-report,login, orfull. get_ssh_client()connects to the selected or automatically resolved ECS address.- An attacker with network interception, routing, DNS, address-redirection, or equivalent man-in-the-middle capability presents a fraudulent SSH server and arbitrary host key.
AutoAddPolicy()accepts the attacker's unknown key without warning or trusted verification.- Password authentication exposes the DevKit ECS credential to the impersonating endpoint.
- The attacker can impersonate the ECS, receive uploaded scripts and commands, retu ...[truncated 671 chars]
- The user or Agent invokes an operation such as
- Remediation
View remediation
Remediation Suggestions
- Replace
paramiko.AutoAddPolicy()withparamiko.RejectPolicy(). - Load host keys from a dedicated, permission-restricted
known_hostsfile before connecting. - Obtain the ECS host-key fingerprint through a trusted provisioning channel, cloud-console metadata, or another authenticated out-of-band mechanism.
- Pin the expected key to the specific ECS identity and reject both unknown and changed keys.
- Do not silently retry after a host-key mismatch; terminate the operation and report a sanitized error.
- Where available, prefer key-based client authentication with a dedicated, least-privileged account, while retaining strict server host-key verification.
- Replace
