Tool Parameter Abuse
- Category
- Tool Misuse
- Confidence
- 80% confidence
- Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- Content
md 3. Before an upload, ask the owner how many whole days the file may remain online. In the same question, offer an optional maximum number of downloads. Use expiryDays as a positive integer, or 0 only if unlimited time was explicit. Use allowedDownloads as the requested positive integer, or 0 for unlimited downloads when the owner declines a cap. For hours or fractional days, explain the API's day granularity and get a compatible choice. Resolve retention before upload. 4. Use Gateway-host exec so the protected key sentinel can be substituted by the egress proxy. Accept only an HTTPS base URL without userinfo, query, or fragment; never follow redirects with the API key. POST multipart file, expiryDays, and allowedDownloads to /api/files/add. Follow references/api-upload.md for the exact request and chunked fallback. Require HTTP success, JSON Result=OK, a valid FileInfo.UrlDownload, and returned expiry/download metadata matching the choices. 5. For upload-only, return the download link and limits to the owner. For an authorized send, deliver only the link to the verified recipient on the requested channel; do not post a private link to a broader chat. Report upload and delivery as distinct outcomes. 6. For an explicit revocation, validate that the link belongs to the configured instance and identify its file ID. DELETE /api/files/delete with the ID in the id header using a key with DELETE permission; omit delay for immediate revocation. Require HTTP 200, then verify GET /api/files/list/{id} returns 404 with VIEW permission. A public download path may return HTTP 200 with an HTML error redirect after deletion; do not treat that status alone as proof the file remains available. Do not delete any other ID. Simple and chunked API uploads do not provide Gokapi end-to-end encryption. If client-side E2EE is required, use Gokapi's encrypted client workflow instead; server-side storage encryption is not E2EE.
