T09 · Insecure Skill Coding Practices
- Location
server.py:24- Finding
TLS Certificate Verification Disabled for Credential-Bearing Requests
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-aligned for VMware Aria Operations sustainability reporting, but it sends an API token over HTTPS with certificate checks disabled and can return fabricated-looking report data after live API failures.
Review before installing. Use only a least-privilege, read-only Aria Operations token; do not run this version on an untrusted network; require proper TLS certificate validation or a trusted CA bundle; and treat simulated fallback metrics as unsafe for reporting unless mock mode is explicitly controlled. Pin dependencies before production use.
server.py:24TLS Certificate Verification Disabled for Credential-Bearing Requests
requirements.txt:1Unpinned Third-Party Dependencies Create Supply-Chain Exposure
server.py:32HTTP Failures Are Replaced with Fabricated Sustainability Metrics
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
try:
# Note: In a live environment, this would target the specific resource ID for the vSphere World/Organization
response = requests.get(url, headers=headers, verify=False)
# Fallback mock data if the specific endpoint isn't fully configured in the user's Aria Ops
if response.status_code != 200:
The skill requires sensitive environment variables and network access but does not declare any explicit tool scope or permission boundaries. That weakens least-privilege controls and makes it easier for an agent or operator to run the skill with broader capabilities than intended, increasing the chance of unauthorized external access or misuse of the API token.
The documentation tells users to configure an API token and connect to VMware Aria Operations but does not clearly warn that the skill will access sensitive organizational sustainability and ESG-related data. This can lead to uninformed deployment, accidental exposure of business-sensitive metrics, and poor token-handling practices by operators who are not made aware of the data sensitivity.
This tool silently uses a credential from the environment to make a network request to an external service without any user-facing disclosure or confirmation. In an MCP/agent context, that can cause users or orchestrators to invoke the tool without realizing it will transmit privileged credentials and query infrastructure data, increasing the chance of unintended data access or privacy/compliance issues.
The request disables TLS certificate verification with verify=False, and the code also suppresses the corresponding warnings globally. This permits man-in-the-middle interception or spoofing of the Aria Operations endpoint, which is especially dangerous because the request carries an API token and retrieves potentially sensitive sustainability and infrastructure data.
try:
# Note: In a live environment, this would target the specific resource ID for the vSphere World/Organization
response = requests.get(url, headers=headers, verify=False)
# Fallback mock data if the specific endpoint isn't fully configured in the user's Aria Ops
if response.status_code != 200:
The dependency mcp is unpinned, which makes builds non-reproducible and can cause the skill to install different versions over time, including versions with known security defects. In an MCP server context, this is more concerning because mcp is a core protocol/runtime dependency and vulnerable releases could directly affect server-side request handling or client trust boundaries.
mcp
requests
mcp has known advisories, and because no version is specified, there is no way to verify that the installed package is not one of the vulnerable releases. This is more dangerous here than in a generic utility because the package underpins an MCP server, so issues such as validation flaws, DNS rebinding weaknesses, or task-access problems could directly expose the service to remote abuse.
The dependency requests is unpinned, so deployments may resolve to different versions with different security properties, including releases affected by known CVEs. Because this skill interfaces with external services, an insecure or unexpectedly changed HTTP client library could expose credentials, weaken TLS-related behavior, or alter request handling in ways that affect confidentiality and integrity.
mcp
requests
requests has multiple published advisories, and leaving it unpinned makes it impossible to confirm whether the deployed version contains a credential leak, verification flaw, or other security issue. Since this skill communicates with VMware Aria Operations and may handle API endpoints and credentials, a vulnerable HTTP client could increase the risk of sensitive data exposure or unsafe outbound connections.
No suspicious patterns detected.