T09 · Insecure Skill Coding Practices
- Location
scripts/create_chat.py:489- Finding
TLS Certificate Verification Disabled for Authenticated Cloud Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create_chat.py:59, 489-501;scripts/run_workflow.py:50, 193-199, 253-257, 532-536, 763-771
Vulnerability Type: Improper Certificate Validation
Risk Level: HighComplete Code Snippet
python # scripts/create_chat.py urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) resp = requests.post( url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers=headers, stream=True, verify=False, timeout=300, proxies={"http": None, "https": None}, )python # scripts/run_workflow.py urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) resp = requests.post( url, data=json.dumps(body, ensure_ascii=False).encode("utf-8"), headers=headers, stream=True, verify=False, timeout=300, proxies={"http": None, "https": None}, ) resp = requests.get( url, headers=headers, verify=False, timeout=60, proxies={"http": None, "https": None}, ) resp = requests.get( url, verify=False, timeout=120, proxies={"http": None, "https": None}, )Technical Analysis
The scripts explicitly pass
verify=Falseto Requests and suppress the resulting insecure-request warnings. Encryption remains in use, but the client does not authenticate the server certificate. Consequently, any certificate presented by an intermediary is accepted.The affected authenticated requests include the OptVerse SSE conversation endpoint, artifact downloads, model-service test artifact retrieval, and downloads from URLs returned in task results. OptVerse requests carry the live IAM token in the
X-Auth-Tokenheader and process user files, chat content, model requests, and generated artifacts.This is a reachable defect during normal Skill operation and does not require malformed user input.
Attack Path
- The user invokes
create_chat.pyor `run_workflo ...[truncated 1132 chars]
- The user invokes
- Remediation
View remediation
Remediation Suggestions
- Remove every
verify=Falseargument and restore Requests' default certificate validation. - Remove global suppression of
InsecureRequestWarning. - If the service requires a private certificate authority, accept a trusted CA bundle through explicit configuration and pass its path through
verify="/path/to/ca-bundle.pem". - Do not provide an unrestricted option that silently disables verification. If a diagnostic override is unavoidable, require explicit user authorization, emit a prominent warning, and prohibit sending credentials while it is enabled.
- Validate that redirects cannot forward authenticated requests to unrelated hosts.
- Rotate IAM tokens that may have been transmitted through an unverified connection.
- Remove every
