T09 · Insecure Skill Coding Practices
- Location
server.py:45- Finding
TLS Certificate Verification Disabled for Authenticated API Requests
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s main purpose is coherent, but it handles an infrastructure API token unsafely and can return simulated compliance findings when live checks fail.
Review before installing. Use only with a narrowly scoped read-only Aria Operations token, restrict the host to your intended internal endpoint, require real TLS certificate validation or a trusted CA bundle, and remove or gate the simulated-report fallback so failed API calls cannot produce fake compliance results. Pin dependencies before production use.
server.py:45TLS Certificate Verification Disabled for Authenticated API Requests
server.py:47Failed API Requests Produce Fabricated Compliance Findings
requirements.txt:1Third-Party Dependencies Are Installed Without Version or Integrity Pinning
The request URL is built from the ARIA_OPS_HOST environment variable and sent with an API token, while TLS certificate validation is explicitly disabled. If an attacker can influence the host value or intercept traffic, they could redirect the request and capture the bearer token or sensitive compliance query data. In this skill’s context, the tool is explicitly intended to reach an internal VMware Aria Operations endpoint, so outbound requests to an attacker-controlled host are especially risky.
}
try:
response = requests.get(url, headers=headers, verify=False)
# Fallback mock data if the API requires a specific UUID or object iteration in the user's environment
if response.status_code != 200:
The skill advertises live compliance checks against the VCF environment, but the fallback emits hard-coded findings unrelated to the actual deployment. This creates integrity risk: operators may make security decisions based on invented violations, or overlook real issues because the tool masks API failures with plausible output.
On any non-200 response, the tool returns a polished simulated compliance report that appears authoritative instead of clearly failing. This can mislead users into acting on fabricated security findings or falsely believing the environment was assessed, which is dangerous for a compliance-scanning skill where trust in result accuracy is essential.
The skill declares and documents use of sensitive environment variables and network access, but does not define any explicit tool scope such as permissions or allowed-tools. That leaves the agent/runtime without a clear least-privilege boundary, increasing the chance the skill can access secrets or make unintended outbound requests beyond what reviewers expect. In this context, the skill connects to VMware Aria Operations using an API token, so unclear scoping is more dangerous because it involves privileged infrastructure and compliance data.
This code reads a sensitive credential from ARIA_OPS_API_TOKEN and sends it in an HTTPS request header, but there is no user-facing print/log message, confirmation, or warning comment/docstring explaining that credentials and host data will be used for a live API call. The docstring describes the feature purpose, but it does not disclose the credential use or outbound transmission behavior.
The code disables TLS certificate verification and suppresses the corresponding warnings, allowing man-in-the-middle interception without visibility to the user. Because the request includes a sensitive Aria Operations API token and targets compliance data in an enterprise environment, this weak default materially increases the chance of credential theft and response tampering.
}
try:
response = requests.get(url, headers=headers, verify=False)
# Fallback mock data if the API requires a specific UUID or object iteration in the user's environment
if response.status_code != 200:
The dependency mcp is unpinned, so installs may resolve to different versions over time, including vulnerable or breaking releases. In an MCP server that interfaces with VMware Aria Operations and performs compliance checks, this increases supply-chain risk because a future install could silently pull a compromised or insecure SDK version into a security-sensitive integration.
mcp
requests
mcp has multiple known advisories, and because no version is pinned, there is no way to verify whether deployment will use a fixed or vulnerable release. This is especially concerning in an MCP server context, where SDK flaws can affect server exposure, client access controls, or request validation in a component that may process sensitive compliance and infrastructure data.
The dependency requests is also unpinned, which makes builds non-reproducible and can introduce vulnerable versions during installation. Because this skill likely makes outbound API calls to VMware Aria Operations, any weakness in the HTTP client library could directly affect authentication, credential handling, or transport security behavior.
mcp
requests
requests has many historical advisories, and without version pinning the actual installed package may be vulnerable. In a tool that communicates with infrastructure management endpoints, this uncertainty can expose secrets, mishandle redirects or URL parsing, or weaken secure request behavior depending on which version gets installed.
No suspicious patterns detected.