T09 · Insecure Skill Coding Practices
- Location
SKILL.md:352- Finding
SSH Host Authentication Disabled for Connections Using a Private Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Ansible helper, but its generated defaults include unsafe infrastructure settings that users should review before installation.
Review and change the generated security defaults before using this skill for real infrastructure: keep SSH host key checking enabled, avoid defaulting to ~/.ssh/id_rsa, require explicit approval for root become, pin dependencies to reviewed versions or commits, store fact caches in a restricted per-project directory, and encrypt or redact any Vault values before committing them.
SKILL.md:352SSH Host Authentication Disabled for Connections Using a Private Key
SKILL.md:416Generated Ansible Dependencies Are Mutable or Not Fully Pinned
SKILL.md:449Unpinned Package Installation in Validation Instructions
SKILL.md:361Ansible Facts Stored in a Predictable Shared Temporary Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
[all:vars] ansible_user=deploy ansible_ssh_private_key_file=~/.ssh/id_rsa ansible_python_interpreter=/usr/bin/python3
The sample ansible.cfg hardcodes a private key file path and also disables host key checking nearby, creating an insecure default connection posture. While not exfiltration code, this encourages users to rely on a fixed sensitive credential path and weakens SSH trust verification, making misuse or man-in-the-middle exposure more likely in copied configurations.
roles_path = ./roles:~/.ansible/roles
collections_paths = ./collections:~/.ansible/collections
remote_user = deploy
private_key_file = ~/.ssh/id_rsa
host_key_checking = False
retry_files_enabled = False
stdout_callback = yaml
The manifest says to use the skill whenever the user mentions a wide range of terms and even for vague requests like "automate server setup." This trigger scope is broad enough to overlap with many general infrastructure conversations, and it does not provide exclusion conditions or negative examples to limit unintended invocation.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
[privilege_escalation]
become = True
become_method = sudo
become_user = root
become_ask_pass = False
The skill explicitly advises using Vault for secrets, yet its example vault.yml contains plaintext-looking credentials and key material. Even if presented as placeholders, examples like this normalize storing secrets directly in files and may be copied into real projects, leading to accidental credential exposure in source control or logs.
L503 says the first line of every file must be '# Managed by Ansible'. Yet examples such as L61 ('# playbooks/.yml'), L173 ('# inventory/hosts'), L198 ('# inventory/hosts.yml'), L247 ('{# templates/nginx.conf.j2 #}'), L324 ('# group_vars/all/vault.yml'), and L337 ('# group_vars/all/vars.yml') put other headers first. That is a direct contradiction between the stated rule and the actual templates the skill tells users to generate.
No suspicious patterns detected.