T09 · Insecure Skill Coding Practices
- Location
references/plugin-usage.md:56- Finding
Automatic retry disables upstream TLS certificate verification
- Content
View full analysis
Vulnerability Details
File Location:
references/plugin-usage.md:56-58; also instructed bySKILL.md:87-88
Vulnerability Type: Improper certificate validation / insecure TLS fallback
Risk Level: HighVulnerable Snippets
From
references/plugin-usage.md:56-58:markdown ## x509 TLS Retry If a `kubectl cce` command returns an `x509` certificate-validation error, repeat the same command with `--cce-insecure-upstream-tls=true` immediately after `cce`. For example: `kubectl cce --cce-insecure-upstream-tls=true --cluster-id <cluster-id> ...`. Use this option only when that TLS validation error occurs.From
SKILL.md:87-88:markdown If a command fails with an x509 upstream TLS validation error, retry that same command once with `--cce-insecure-upstream-tls=true` immediately after `cce`.Technical Analysis
The Skill directs the Agent to automatically repeat a failed CCE resource query with upstream TLS certificate validation disabled. A certificate-validation failure is a security boundary: it indicates that the client cannot authenticate the remote endpoint. Turning verification off in response converts that failure into an unauthenticated connection.
The retry does not require separate user approval, certificate fingerprint verification, a user-approved private certificate authority, or any equivalent endpoint-authentication mechanism. The same authenticated query is repeated, potentially including plugin credentials supplied through environment variables or CLI options.
This is reachable during the Skill's documented resource-query workflow whenever the upstream connection reports an x509 validation error. Although the insecure mode is conditional and limited to one retry, that condition does not prevent exploitation because a network-path attacker can induce the certificate error by presenting an untrusted certificate.
Attack Path
- The user authorizes a read-only
kubectl ccequery against a specified ...[truncated 1312 chars]
- The user authorizes a read-only
- Remediation
View remediation
Remediation Suggestions
- Remove the automatic
--cce-insecure-upstream-tls=trueretry from bothSKILL.mdandreferences/plugin-usage.md. - Treat every x509 validation error as a hard failure and stop the query.
- Direct the user to repair the certificate trust chain, verify system time, confirm the configured endpoint, or install the appropriate trusted CA certificate.
- If insecure TLS must remain available for exceptional diagnostics, require explicit per-command user approval after displaying the affected endpoint and interception risk.
- Do not transmit credentials during an insecure diagnostic connection. Use a non-authenticated connectivity check where possible.
- For private certificate deployments, support an explicit CA bundle or pinned certificate/public-key fingerprint instead of disabling verification.
- Add acceptance tests confirming that certificate failures cannot silently or automatically transition to an insecure authenticated connection.
- Remove the automatic
