T09 · Insecure Skill Coding Practices
- Location
scripts/ssh_client.py:245- Finding
SSH Connections Accept Unverified Host Keys
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ssh_client.py, lines 245–249
Vulnerability Type: Missing SSH server identity verification
Risk Level: HighVulnerable Code
python client = paramiko.SSHClient() client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) try: client.connect( hostname=host,Technical Analysis
The unified SSH client configures Paramiko with
AutoAddPolicy, which automatically trusts any host key presented by a server when the host is not already known. The code does not load a trusted known-hosts file, pin an expected key or fingerprint, or require first-use fingerprint confirmation.This affects every operation using
_paramiko_connect, including remote command execution, file uploads, directory uploads, report downloads, and the initial connection test. Password authentication does not authenticate the server to the client; it only authenticates the client to whichever endpoint completed the SSH handshake.The password is removed from
os.environafter connection, but that does not mitigate disclosure to an impersonating SSH endpoint because the password has already been submitted during authentication.Attack Path
- The user configures an authorized remote server through
KUNPENG_SERVER_HOST, or the provisioning process stores the new server address. - A network-positioned attacker intercepts or redirects the connection through DNS spoofing, routing manipulation, a compromised gateway, or another applicable network attack.
- The attacker presents an arbitrary SSH host key.
AutoAddPolicyaccepts that key without warning or verification.- The client submits
MIGRATE_SSH_PASSto the impersonating endpoint. - The attacker captures the root or privileged SSH password.
- The attacker can subsequently authenticate to the legitimate server if it is reachable. The attacker may also return forged command output, receive uploaded source or installation files, or provide m ...[truncated 747 chars]
- The user configures an authorized remote server through
- Remediation
View remediation
Remediation Suggestions
- Replace
AutoAddPolicywith strict host-key rejection:
python client = paramiko.SSHClient() client.load_system_host_keys() client.load_host_keys(user_known_hosts_path) client.set_missing_host_key_policy(paramiko.RejectPolicy())- For newly provisioned servers, obtain the expected host-key fingerprint through a trusted cloud control-plane channel or console and compare it before password authentication.
- If trust-on-first-use is necessary, display the SHA-256 fingerprint and require explicit out-of-band user verification before persisting it.
- Store accepted keys in a user-owned known-hosts file with restrictive permissions.
- Reject changed keys and provide an explicit warning rather than silently replacing or accepting them.
- Apply the same verification procedure to direct Paramiko examples in the Skill documentation so agents do not bypass the hardened helper.
- Replace
