Skip to content

[Security] TLS verification disabled in RedisCache + autonomous code execution in AutoGPT node #5979

@hhhashexe

Description

@hhhashexe

Found via SkillFence automated scan.

Finding 1: RedisCache.ts — TLS verification disabled, enabling MITM attacks on cached data.

Finding 2: AutoGPT.ts — Autonomous agent with unrestricted code execution capability.

Recommendation:

  • Enable TLS verification by default for Redis connections
  • Add sandboxing/approval gates for autonomous code execution

Scan: npx skillfence scan . (Verdict: BLOCK, 16 critical, 43 high)

Responsible disclosure via automated security scanning.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions