Back to skill

Security audit

Temp Access Link

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent temporary file-link service, but it needs review because it handles sensitive files through an external API with unclear authorization, retention, and token-handling controls.

Review this skill before installing for any confidential or regulated workflow. Do not upload sensitive documents or submit internal file URLs unless you trust the api.mkkpro.com provider and have confirmed its authentication, storage, logging, deletion, retention, and compliance controls. The provider should clarify whether /files/{filename} can be accessed without a valid token and how token-bearing URLs are protected from logging and replay.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
openapi.json:99
Finding

File-serving endpoint does not specify token-based authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:83
Finding

Bearer-style access tokens are exposed in URL paths

Content
View full analysis
Remediation
View remediation
`. 3. For browser-based sharing, use the URL value as a short-lived, one-time exchange code: - Redeem it through a POST request. - Immediately invalidate it after redemption. - Establish a protected, narrowly scoped session for the download. 4. Use cryptographically random, high-entropy tokens with short expiration periods. 5. Bind tokens to the exact file, operation, audience, and intended use count. 6. Redact access paths and token values from proxy, gateway, application, analytics, tracing, and monitoring logs. 7. Apply `Referrer-Policy: no-referrer` and appropriate cache-control headers to access and download responses. 8. Prevent third-party resources from loading on token-bearing pages to reduce accidental disclosure. 9. Implement token revocation and replay detection, especially where links are advertised as single-use. 10. Document token storage, retention, logging, expiration, and incident-response requirements. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
The Temporary Access Link Generator is a security-focused API that enables the creation of time-limited, single-use or restricted-access links for secure file distribution. Built with security best practices, this tool allows organizations to share sensitive files without exposing permanent URLs or relying on third-party file-sharing services.

Key capabilities include generating expiring access tokens, uploading files with automatic link generation, and serving files through secured token-based access. This is ideal for security teams needing to distribute sensitive documentation, incident reports, or confidential materials to authorized recipients with guaranteed expiration windows.

The tool is particularly valuable for compliance scenarios, incident response workflows, and any situation where time-bound access to files is required. All access is tracked and automatically revoked after the specified expiration period.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
### POST /generate-link

Generates a temporary access token for an existing file URL with automatic expiration.

**Parameters:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
### POST /generate-link

Generates a temporary access token for an existing file URL with automatic expiration.

**Parameters:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This sample response shows generated access URLs hosted on an external domain, confirming that file-sharing metadata and access operations depend on a third-party service. For sensitive-file workflows, external transmission materially increases confidentiality and compliance risk if users are not fully informed.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

json
{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "access_url": "https://api.mkkpro.com/tools/temp-access-link/access/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_at": "2024-01-15T14:30:00Z",
  "status": "success"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to upload files and submit file URLs without clearly warning that this data is sent to an external third-party API service. This can cause inadvertent disclosure of sensitive documents, internal URLs, or regulated data by users who assume processing is local or first-party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The upload workflow returns an access URL on the external api.mkkpro.com domain, implying that uploaded file contents are transmitted to and stored or processed by a third-party service. Because the skill is marketed for sharing sensitive audit and incident-response materials, this creates substantial data-exposure risk if organizational approval, retention controls, and user consent are absent.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

{ "filename": "sensitive_audit.pdf", "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "access_url": "https://api.mkkpro.com/tools/temp-access-link/access/eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "status": "uploaded" }

text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents a direct file-serving endpoint by filename but does not state that this endpoint independently enforces token validation or authorization. In a tool whose security model is based on expiring links, an unauthenticated or weakly checked /files/{filename} route could let attackers bypass expiration controls and retrieve files directly if filenames are guessable or leaked.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
## References

- **Kong Route:** https://api.mkkpro.com/tools/temp-access-link
- **API Docs:** https://api.mkkpro.com:8030/docs

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest and API description do not define clear activation scope, allowed destinations, or usage constraints for link generation and file upload. In an agent setting, this ambiguity can cause the tool to be invoked for arbitrary URLs or files, enabling misuse for unapproved sharing, persistence, or exfiltration workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims to generate temporary access links, but the API also exposes direct file upload and direct file-serving endpoints. This expands capability beyond the stated purpose and can let an agent store and retrieve arbitrary files directly, increasing the chance of data exfiltration, unintended hosting, or bypass of any temporary-link controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

The visible operation summaries and titles are all fixed in English, and the file does not indicate any user language choice or locale handling. While this may be acceptable for internal APIs, it can be a policy concern if the skill is expected to support multilingual users and no opt-in language behavior is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.