T09 · Insecure Skill Coding Practices
- Location
scripts/collect_ai_hot_news.py:33- Finding
External Feed Integrity Can Be Bypassed Through Plaintext HTTP and Disabled TLS Verification
- Content
View full analysis
bytes: request = urllib.request.Request( url, headers={"User-Agent": "Codex AI hot news collector/1.0"}, ) context = ssl._create_unverified_context() if insecure else None with urllib.request.urlopen(request, timeout=timeout, context=context) as response: return response.read() ``` ```python for feed, region in selected_feeds(region_filter): try: payload = fetch(feed, insecure=insecure) for candidate in iter_items(feed, payload, region): published = published_dt(candidate) if published is None or published >= cutoff: candidates.append(candidate) ``` The documented workflow also exposes the insecure mode: ```markdown 1. Get current candidates from live sources. Prefer the bundled collector: python scripts/collect_ai_hot_news.py --hours 24 --region all --limit 40 --output /tmp/ai-hot-news.json 2. If the local Python certificate store is broken, fix the certificate store first. For a one-off local debug run only, use `--insecure` and ...[truncated 2452 chars]- Remediation
View remediation
