T05 · Unauthorized Access and Privilege Escalation
- Location
openapi.json:99- Finding
File-serving endpoint does not specify token-based authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent temporary file-link service, but it needs review because it handles sensitive files through an external API with unclear authorization, retention, and token-handling controls.
Review this skill before installing for any confidential or regulated workflow. Do not upload sensitive documents or submit internal file URLs unless you trust the api.mkkpro.com provider and have confirmed its authentication, storage, logging, deletion, retention, and compliance controls. The provider should clarify whether /files/{filename} can be accessed without a valid token and how token-bearing URLs are protected from logging and replay.
openapi.json:99File-serving endpoint does not specify token-based authorization
SKILL.md:83Bearer-style access tokens are exposed in URL paths
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
The Temporary Access Link Generator is a security-focused API that enables the creation of time-limited, single-use or restricted-access links for secure file distribution. Built with security best practices, this tool allows organizations to share sensitive files without exposing permanent URLs or relying on third-party file-sharing services.
Key capabilities include generating expiring access tokens, uploading files with automatic link generation, and serving files through secured token-based access. This is ideal for security teams needing to distribute sensitive documentation, incident reports, or confidential materials to authorized recipients with guaranteed expiration windows.
The tool is particularly valuable for compliance scenarios, incident response workflows, and any situation where time-bound access to files is required. All access is tracked and automatically revoked after the specified expiration period.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### POST /generate-link
Generates a temporary access token for an existing file URL with automatic expiration.
**Parameters:**
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### POST /generate-link
Generates a temporary access token for an existing file URL with automatic expiration.
**Parameters:**
This sample response shows generated access URLs hosted on an external domain, confirming that file-sharing metadata and access operations depend on a third-party service. For sensitive-file workflows, external transmission materially increases confidentiality and compliance risk if users are not fully informed.
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"access_url": "https://api.mkkpro.com/tools/temp-access-link/access/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"expires_at": "2024-01-15T14:30:00Z",
"status": "success"
}
The skill encourages users to upload files and submit file URLs without clearly warning that this data is sent to an external third-party API service. This can cause inadvertent disclosure of sensitive documents, internal URLs, or regulated data by users who assume processing is local or first-party.
The upload workflow returns an access URL on the external api.mkkpro.com domain, implying that uploaded file contents are transmitted to and stored or processed by a third-party service. Because the skill is marketed for sharing sensitive audit and incident-response materials, this creates substantial data-exposure risk if organizational approval, retention controls, and user consent are absent.
{ "filename": "sensitive_audit.pdf", "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "access_url": "https://api.mkkpro.com/tools/temp-access-link/access/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "status": "uploaded" }
The skill documents a direct file-serving endpoint by filename but does not state that this endpoint independently enforces token validation or authorization. In a tool whose security model is based on expiring links, an unauthenticated or weakly checked /files/{filename} route could let attackers bypass expiration controls and retrieve files directly if filenames are guessable or leaked.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## References
- **Kong Route:** https://api.mkkpro.com/tools/temp-access-link
- **API Docs:** https://api.mkkpro.com:8030/docs
The manifest and API description do not define clear activation scope, allowed destinations, or usage constraints for link generation and file upload. In an agent setting, this ambiguity can cause the tool to be invoked for arbitrary URLs or files, enabling misuse for unapproved sharing, persistence, or exfiltration workflows.
The skill claims to generate temporary access links, but the API also exposes direct file upload and direct file-serving endpoints. This expands capability beyond the stated purpose and can let an agent store and retrieve arbitrary files directly, increasing the chance of data exfiltration, unintended hosting, or bypass of any temporary-link controls.
The visible operation summaries and titles are all fixed in English, and the file does not indicate any user language choice or locale handling. While this may be acceptable for internal APIs, it can be a policy concern if the skill is expected to support multilingual users and no opt-in language behavior is documented.
No suspicious patterns detected.