T09 · Insecure Skill Coding Practices
- Location
SKILL.md:60- Finding
TLS Certificate Verification Disabled for Authenticated Cloud API Traffic
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60–65
Vulnerability Type: Improper certificate validation
Risk Level: MediumCode snippet:
markdown ### Authentication Configuration - AK/SK configured in `~/.hcloud/config.json` - Default region: `cn-north-4` - `project_id` configured in profile - `skipSecureVerify=true` (for WSL environment)Technical Analysis
The Skill instructs WSL users to configure
skipSecureVerify=truealongside their authenticated hcloud profile. This disables validation of the server certificate used for cloud API connections.Consequently, possession of a certificate trusted by the client is no longer required to impersonate the remote endpoint. A network-positioned attacker could intercept authenticated ModelArts requests, observe returned job information and logs, or provide forged API responses. The Skill then treats fields from those responses—such as tracebacks, events, and failure-analysis results—as trusted diagnostic evidence.
The documented setting is not constrained to a one-time connectivity test, and no compensating control such as certificate pinning or a private CA configuration is specified.
Attack Path
- A WSL user follows the prerequisite and enables
skipSecureVerify=truein the hcloud configuration. - The user invokes the Skill to diagnose a ModelArts training job.
- The Skill executes authenticated hcloud requests for job details, events, stages, or logs.
- An attacker with a network interception position presents an untrusted certificate and impersonates the cloud endpoint.
- Because certificate verification is disabled, the CLI accepts the connection.
- The attacker can observe API traffic and return manipulated job metadata, diagnostic events, log content, or temporary log-link responses.
- The Skill may disclose sensitive diagnostic data to the interceptor or generate false conclusions and remediation advice fro ...[truncated 539 chars]
- A WSL user follows the prerequisite and enables
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to set
skipSecureVerify=true. - Keep TLS certificate verification enabled for all authenticated cloud API operations.
- Resolve WSL certificate errors by installing the appropriate CA chain and configuring hcloud to use the correct trusted CA store.
- If disabling verification is retained solely for troubleshooting, make it an explicit, temporary, user-confirmed diagnostic step that does not send credentials or access sensitive resources.
- Document how to restore secure verification immediately after troubleshooting.
- Add a preflight check that refuses authenticated diagnosis when secure certificate verification is disabled.
- Remove the instruction to set
