Back to skill

Security audit

gokapi-file-sharing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Gokapi file-sharing helper that asks for user-controlled setup, upload limits, recipient scope, and revocation before acting.

Install only if you trust the configured Gokapi instance and are comfortable storing a scoped Gokapi API key. Prefer least-privilege keys, allow egress only to your instance hostname, remember API uploads are not end-to-end encrypted, and verify retention/download limits before sharing sensitive files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
3. Before an upload, ask the owner how many whole days the file may remain online. In the same question, offer an optional maximum number of downloads. Use expiryDays as a positive integer, or 0 only if unlimited time was explicit. Use allowedDownloads as the requested positive integer, or 0 for unlimited downloads when the owner declines a cap. For hours or fractional days, explain the API's day granularity and get a compatible choice. Resolve retention before upload.
4. Use Gateway-host exec so the protected key sentinel can be substituted by the egress proxy. Accept only an HTTPS base URL without userinfo, query, or fragment; never follow redirects with the API key. POST multipart file, expiryDays, and allowedDownloads to /api/files/add. Follow references/api-upload.md for the exact request and chunked fallback. Require HTTP success, JSON Result=OK, a valid FileInfo.UrlDownload, and returned expiry/download metadata matching the choices.
5. For upload-only, return the download link and limits to the owner. For an authorized send, deliver only the link to the verified recipient on the requested channel; do not post a private link to a broader chat. Report upload and delivery as distinct outcomes.
6. For an explicit revocation, validate that the link belongs to the configured instance and identify its file ID. DELETE /api/files/delete with the ID in the id header using a key with DELETE permission; omit delay for immediate revocation. Require HTTP 200, then verify GET /api/files/list/{id} returns 404 with VIEW permission. A public download path may return HTTP 200 with an HTML error redirect after deletion; do not treat that status alone as proof the file remains available. Do not delete any other ID.

Simple and chunked API uploads do not provide Gokapi end-to-end encryption. If client-side E2EE is required, use Gokapi's encrypted client workflow instead; server-side storage encryption is not E2EE.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-upload.md (reported line 27)May include surrounding context.

md
3. Before an upload, ask the owner how many whole days the file may remain online. In the same question, offer an optional maximum number of downloads. Use expiryDays as a positive integer, or 0 only if unlimited time was explicit. Use allowedDownloads as the requested positive integer, or 0 for unlimited downloads when the owner declines a cap. For hours or fractional days, explain the API's day granularity and get a compatible choice. Resolve retention before upload.
4. Use Gateway-host exec so the protected key sentinel can be substituted by the egress proxy. Accept only an HTTPS base URL without userinfo, query, or fragment; never follow redirects with the API key. POST multipart file, expiryDays, and allowedDownloads to /api/files/add. Follow references/api-upload.md for the exact request and chunked fallback. Require HTTP success, JSON Result=OK, a valid FileInfo.UrlDownload, and returned expiry/download metadata matching the choices.
5. For upload-only, return the download link and limits to the owner. For an authorized send, deliver only the link to the verified recipient on the requested channel; do not post a private link to a broader chat. Report upload and delivery as distinct outcomes.
6. For an explicit revocation, validate that the link belongs to the configured instance and identify its file ID. DELETE /api/files/delete with the ID in the id header using a key with DELETE permission; omit delay for immediate revocation. Require HTTP 200, then verify GET /api/files/list/{id} returns 404 with VIEW permission. A public download path may return HTTP 200 with an HTML error redirect after deletion; do not treat that status alone as proof the file remains available. Do not delete any other ID.

Simple and chunked API uploads do not provide Gokapi end-to-end encryption. If client-side E2EE is required, use Gokapi's encrypted client workflow instead; server-side storage encryption is not E2EE.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
# Gokapi file sharing

1. For a requested file send to anyone other than the agent's owner, use Gokapi unless the owner explicitly chose another transport. If the owner describes a self-directed transfer as large, or the file exceeds the chosen channel's known attachment limit, proactively offer Gokapi but do not upload until the owner accepts. Do not invent a universal size threshold; compare the actual file size to channel limits when available. Also run for explicit setup, upload, or link revocation. Identify the exact file or Gokapi link and intended recipient/channel. Verify authority for upload, external delivery, or deletion; stop if identity or scope is unresolved.
2. On first setup, list local secret-entry and skill-binding metadata. Treat GOKAPI_BASE_URL and GOKAPI_API_KEY as two independent inputs. If no valid URL binding exists, ask the owner for their Gokapi HTTPS base URL; never infer it from a publisher domain, API documentation, or an API key. If a URL is already configured, report its hostname and use it without asking again unless the owner wants to change it. Store a new URL as an env-kind GOKAPI_BASE_URL entry through the local CLI or Settings using stdin/value-file, then bind its store SecretRef to skills.entries.gokapi-file-sharing.apiKey using the local store-provider alias. OpenClaw's generic apiKey field is only the primaryEnv injection path for the URL; do not use an API-key-labeled prompt for the URL or store it as a secret-kind entry. Separately request GOKAPI_API_KEY through a masked secret prompt, restricted to the exact configured hostname. If the protected prompt is unavailable, follow references/setup.md for a local masked-CLI fallback; never request the key in chat. Confirm both entries and Gateway egress are usable without printing the key. Installation alone does not run this setup; do it when the skill is first invoked or setup is requested.
3. Before an upload, ask the owner how many whole days the file may remain online. In the
...[truncated 26 chars]

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Static analysis

No suspicious patterns detected.