T09 · Insecure Skill Coding Practices
- Location
scripts/sec_finance.py:104- Finding
Automatic fallback to unverified HTTPS connections
- Content
View full analysis
ssl.SSLContext: ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE return ctx def _get_json(url: str, timeout: int = 20, retries: int = 2) -> dict: parsed = urllib.parse.urlparse(url) last_error = None for attempt in range(retries + 1): req = urllib.request.Request( url, headers={ "User-Agent": USER_AGENT, "Accept": "application/json", "Host": parsed.netloc, }, ) for ctx_factory in (_secure_ctx, _fallback_insecure_ctx): try: with urllib.request.urlopen(req, timeout=timeout, context=ctx_factory()) as resp: return json.loads(resp.read()) except ssl.SSLError as e: last_error = e continue except urllib.error.HTTPError as e: if e.code == 429 and attempt < retries: time.sleep(3 * (attempt + 1)) last_error = e break if e.code == 404: raise ValueError(f"CIK or resource not found: {url}") from e raise ValueError(f"HTTP {e.code} fetching {url}: {e.reason}") from e except urllib.error.URLError as e: last_error = e continue if attempt < retries: time.sleep(1.5 ** attempt) raise ConnectionError(f"Network/SSL error fetching {url}: {last_error}") def _get_text(url: str, timeout: int = 20) -> str: req = urllib.request.Request(url, headers={"User-Agent": USER_AGENT}) last_error = None for ctx_factory in (_secure_ctx, _fallback_insecure_ctx): tr ...[truncated 2762 chars]- Remediation
View remediation
ssl.SSLContext: return ssl.create_default_context() ``` 3. Replace both context loops with a single verified request: ```python with urllib.request.urlopen( req, timeout=timeout, context=_secure_ctx(), ) as resp: return json.loads(resp.read()) ``` 4. Treat certificate failures as terminal security errors and report them clearly rather than retrying insecurely. 5. If the runtime requires a private or custom certificate authority, explicitly load a controlled CA bundle: ```python ctx = ssl.create_default_context(cafile="/path/to/trusted-ca-bundle.pem") ``` 6. Do not disable hostname verification or use `ssl.CERT_NONE` in production. 7. Add automated tests confirming that self-signed, expired, untrusted, and hostname-mismatched certificates are rejected. 8. Consider enforcing an allowlist for remote hostnames so future changes cannot redirect requests away from the intended SEC domains. ]]>
