Back to skill

Security audit

VCF Log Explorer (MCP)

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated log-search purpose, but it uses a sensitive API token to fetch raw infrastructure logs while disabling TLS certificate verification.

Review before installing. Use only a least-privilege read-only Log Insight token, avoid running this against sensitive logs until TLS verification is fixed, pin dependencies, and add clear query/redaction controls for data returned to the agent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
server.py:6
Finding

TLS Certificate Verification Disabled for Authenticated API Requests

Content
View full analysis

Vulnerability Details

File Location: server.py:6-7, 28-34
Vulnerability Type: Improper certificate validation
Risk Level: High

Vulnerable Code

python
# Disable insecure request warnings for VCF self-signed certs
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
python
url = f"https://{host}/api/v1/events?keyword={keyword}&limit={limit}"
headers = {
    "Authorization": f"Bearer {token}",
    "Accept": "application/json"
}

try:
    response = requests.get(url, headers=headers, verify=False)

Technical Analysis

The authenticated request explicitly sets verify=False, causing the Requests library to accept any TLS certificate presented by the remote endpoint. Globally suppressing InsecureRequestWarning also conceals the resulting security warning.

HTTPS encryption without certificate validation does not authenticate the server. An attacker with a network interception position can impersonate the configured Log Insight server using an arbitrary certificate. The client will then transmit the bearer token to the attacker's endpoint. The attacker can also return manipulated JSON events that are formatted and supplied to the AI agent as trusted log results.

The host is provided through an environment variable, which is appropriate for deployment configuration, but it does not mitigate interception or DNS manipulation when server identity is not verified.

Attack Path

  1. A legitimate operator configures LOGINSIGHT_HOST and LOGINSIGHT_API_TOKEN.
  2. An attacker obtains a network interception position or manipulates DNS/routing for the configured host.
  3. The attacker presents an arbitrary or self-signed certificate while impersonating the Log Insight server.
  4. Because verify=False is set, the MCP server accepts the attacker's certificate without validation.
  5. The server sends the Authorization: Bearer header to the attacker.
  6. The a ...[truncated 850 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove verify=False and use the Requests library's default certificate validation:
    python
    response = requests.get(
        url,
        headers=headers,
        params={"keyword": keyword, "limit": limit},
        timeout=30,
    )
    
  • For private deployments using a self-signed or privately issued certificate, install the organization's CA certificate in the system trust store or provide a configurable CA bundle:
    python
    ca_bundle = os.getenv("LOGINSIGHT_CA_BUNDLE", True)
    response = requests.get(
        f"https://{host}/api/v1/events",
        headers=headers,
        params={"keyword": keyword, "limit": limit},
        verify=ca_bundle,
        timeout=30,
    )
    
  • Remove the global urllib3.disable_warnings(...) call so certificate problems remain visible.
  • Restrict the API token to the minimum read-only permissions required for event searches.
  • Rotate the existing token if the server has operated across an untrusted network while verification was disabled.
  • Consider validating LOGINSIGHT_HOST against an administrator-controlled allowlist to reduce accidental or malicious redirection.

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Non-reproducible and insufficiently constrained dependency installation
Risk Level: Medium

Vulnerable Code

text
mcp
requests

The documented installation procedure in SKILL.md:23 installs these unconstrained dependencies:

text
pip install -r requirements.txt

Technical Analysis

Neither dependency has an exact version or integrity hash. Every installation may therefore resolve to a different package release. This prevents reproducible builds and means newly published package versions are trusted without project-level review.

Unpinned dependencies do not prove that the current packages are malicious. However, they create a supply-chain exposure: a compromised upstream release, malicious package publication, or unexpected breaking release could be selected automatically during a future installation. Python packages may execute code during installation or when imported by server.py.

Attack Path

  1. An operator follows the documented command pip install -r requirements.txt.
  2. The package index resolves mcp and requests to whatever releases currently satisfy the unconstrained entries.
  3. An upstream account, package release, distribution artifact, or dependency in the resolved dependency graph is compromised or changes unexpectedly.
  4. The affected package is downloaded and installed without a project-controlled version or hash check.
  5. Malicious code may execute during installation or later when requests or mcp.server.fastmcp is imported.
  6. That code runs with the privileges of the account installing or launching the MCP server.

Impact Assessment

Exploitation could permit arbitrary Python code execution in the installation or MCP server process. The resulting privileges are limited to those of the user or service account running pip or the server, but could include acces ...[truncated 311 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin all direct and transitive dependencies to reviewed versions using a lock file generated in a controlled environment.
  • Require cryptographic hashes for all downloaded distributions. For example:
    text
    mcp==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH
    requests==REVIEWED_VERSION --hash=sha256:REVIEWED_HASH
    
  • Install with hash enforcement:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  • Generate and review transitive dependency pins with a dependency-management tool such as pip-tools.
  • Use a trusted package index, disable unintended extra indexes, and review dependency provenance before upgrades.
  • Run automated vulnerability and dependency-update monitoring, while requiring review and testing before accepting new versions.
  • Install and run the MCP server under a dedicated, least-privileged service account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'url' from os.getenv (line 27, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · server.py (reported line 34)May include surrounding context.

python
}

    try:
        response = requests.get(url, headers=headers, verify=False)
        response.raise_for_status()
        data = response.json()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes networked log-search capability and requires sensitive environment variables, but it does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens governance and least-privilege controls, making it easier for an agent or downstream workflow to invoke a powerful MCP server without clear policy boundaries around network access and secret use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This tool is explicitly designed to retrieve and return log entries, which often contain sensitive operational details, usernames, IPs, tokens, and error traces. In an MCP/agent context, returning raw logs directly to the requester without access controls, redaction, or a clear disclosure materially increases the risk of sensitive data exposure.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
99% confidence
Finding

The code disables TLS certificate verification with verify=False and suppresses the related warnings globally. This allows man-in-the-middle interception or modification of API traffic, exposing the bearer token and any returned log data, which is especially dangerous because the tool accesses sensitive infrastructure logs.

Content

Scanner excerpt · server.py (reported line 34)May include surrounding context.

python
}

    try:
        response = requests.get(url, headers=headers, verify=False)
        response.raise_for_status()
        data = response.json()

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency mcp is unpinned, so installs may resolve to different versions over time, including vulnerable or incompatible releases. In an MCP server context, this is more concerning because mcp is part of the server's core protocol and runtime behavior, so an unsafe upstream release could directly affect exposed tool functionality.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
mcp
requests

Unverifiable Dependency: mcp has 12 known advisory(ies) (CVE-2025-53366 (MCP Python SDK vulnerability in the FastMCP Server causes validation error, lead); CVE-2025-66416 (Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection); CVE-2026-52870 (MCP Python SDK: Experimental task handlers allow any client to access and cancel) +9 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

mcp has known advisories, and because no version is pinned, there is no way to verify whether deployment will install a patched or vulnerable release. This matters more here than in a passive library because the package underpins an MCP server, increasing the chance that protocol-handling or server-side flaws could be exposed to connected clients.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency requests is also unpinned, which makes builds non-reproducible and may pull in a vulnerable version depending on install time and environment. Because this skill dynamically queries VMware Aria Operations for Logs over the network, weaknesses in the HTTP client library could affect outbound request security or credential handling.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
mcp
requests

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

requests has multiple known advisories, and the absence of version pinning makes it impossible to determine whether the installed package is safe. Since this skill likely performs authenticated HTTP requests to a log platform, a vulnerable requests version could increase the risk of credential leakage, TLS/verification issues, or other client-side request handling flaws.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The function reads LOGINSIGHT_API_TOKEN from the environment to authenticate to an external service. While this is necessary for operation, there is no visible warning or disclosure to the user that stored credentials will be used to access backend systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.