T09 · Insecure Skill Coding Practices
- Location
references/setup.md:15- Finding
Default Quick-Install Command Exposes an Unauthenticated Service on All Network Interfaces
- Content
View full analysis
- Remediation
View remediation
``` 2. Require a strong authentication token during initial installation rather than presenting it as an optional follow-up hardening step. 3. Refuse to start without authentication when the server is configured to listen on a non-loopback address, unless an explicit unsafe-development override is supplied. 4. Place any remotely accessible deployment behind a TLS-terminating reverse proxy. 5. Add per-client rate limits, request quotas, upload quotas, and enforced asynchronous-job concurrency limits. 6. Apply authentication and authorization consistently to file listing, download, deletion, job control, and processing endpoints. 7. Use network firewall rules or a private overlay network such as WireGuard or Tailscale to restrict reachability. 8. Monitor disk, CPU, GPU, and job-queue usage, and automatically reject work when configured resource thresholds are reached. ]]>
