T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Plaintext SSH Credential Collection Through Agent Conversation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 84–86 and 97–103
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: MediumVulnerable Code Snippet
markdown 2. **SSH 访问方式**(二选一): - 方式 A:提供用户名和密码 - 方式 B:提前配置好 SSH 信任关系(推荐)The document then demonstrates submission of a plaintext credential:
markdown **示例用户输入**:有 3 台虚拟机:
- 10.0.2.7 (Control Plane)
- 10.0.2.8 (Worker)
- 10.0.2.9 (Worker) SSH: worker/work@123 K8S 版本:官方最新版本(v1.35)
text Technical Analysis
The Skill explicitly permits users to provide an SSH username and password directly to the AI Agent and reinforces that workflow with a plaintext password example. It provides no protected secret-input mechanism, credential-redaction requirement, retention policy, or prohibition against copying credentials into generated configuration, reports, logs, inventories, or Agent context.
Although SSH authentication is relevant to remote Kubernetes deployment, reusable passwords should not be submitted through ordinary conversational channels. Such content may be retained in conversation history, telemetry, execution context, or derived artifacts. Key-based SSH trust is only recommended, not required, and the document does not mandate short-lived or least-privilege credentials.
Attack Path
- The Agent loads the Skill and asks the user for an SSH access method.
- Following the documented option and example, the user submits a reusable SSH username and password in the conversation.
- The credential is retained in chat history, Agent context, telemetry, or a generated deployment artifact.
- An unauthorized party gains access to one of those records.
- The party extracts the credential and authenticates to the listed Kubernetes nodes.
- If the account has the elevated deployment permissions anticipated by the Skill, the party can modify hosts or compromise the cluster.
I
...[truncated 620 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove password submission through Agent conversations as a supported authentication method.
- Require preconfigured public-key authentication, an SSH agent, short-lived SSH certificates, or another ephemeral authentication mechanism.
- If passwords must be supported, collect them through a protected interactive prompt or approved secret manager that does not expose the value to chat history or logs.
- Require dedicated, time-limited deployment accounts with narrowly scoped
sudopermissions instead of direct root access or broadly privileged reusable accounts. - Explicitly prohibit credentials from being written to reports, inventories, configuration files, command-line arguments, telemetry, or logs.
- Add mandatory redaction rules for all command output and generated artifacts.
- Define credential rotation and revocation procedures following deployment.
- Replace the plaintext example with a non-secret placeholder such as
SSH authentication: preconfigured SSH agent.
