Back to skill

Security audit

Okfile

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for uploading and publishing files to OkFile, with expected external sharing risk that users should understand.

Install or use this only for files and folders you intend to send to OkFile and potentially make accessible through generated links or subdomains. Avoid uploading secrets, credentials, internal documents, or private folders unless you explicitly want them shared, and be cautious with the optional CLI install because it relies on external package distribution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

External CLI Installation Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 96-110; equivalent installation guidance is repeated at lines 329-337
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
### Python CLI Install
Prefer installing the latest published PyPI package:
```bash
py -3 -m pip install okfile
okfile --version

If you need a pinned install for reproducibility:

bash
py -3 -m pip install okfile==1.2.3

Upgrade an existing install:

bash
py -3 -m pip install --upgrade okfile

If you need a direct static artifact instead of PyPI, install the wheel from OkFile:

bash
py -3 -m pip install "https://www.okfile.com/downloads/okfile-1.2.3-py3-none-any.whl"
text

### Technical Analysis

The Skill instructs users or agents to download, install, and execute an external Python package that is not included in the audited project. The default installation and upgrade commands do not pin a version, so the downloaded implementation can change after this Skill has been reviewed. Although one command pins version `1.2.3`, neither that command nor the vendor-hosted wheel installation verifies a cryptographic hash or signature.

The repository contains only `SKILL.md`; therefore, the effective behavior of the installed `okfile` executable cannot be verified from the audited artifact. This creates a supply-chain trust boundary around the PyPI package, its maintainer account, package distribution infrastructure, the vendor website, and the downloaded artifact.

This finding does not establish that the current package is malicious. The risk arises because the instructions allow unreviewed or subsequently modified third-party code to be installed and executed without integrity validation.

### Attack Path

1. An attacker compromises the package publisher account, package registry, vendor download infrastructure, or a future package release.
...[truncated 1291 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact, reviewed version instead of recommending an unversioned installation or automatic upgrade.
  2. Publish and document a trusted SHA-256 digest for the approved wheel.
  3. Require hash verification, preferably through a locked requirements file and pip's --require-hashes option.
  4. Avoid direct vendor-hosted artifact installation unless the artifact is authenticated through a verified signature or pinned cryptographic digest.
  5. Vendor the reviewed CLI source or wheel within a controlled release process when feasible, so its contents are covered by the Skill audit.
  6. Remove or discourage pip install --upgrade okfile from automated workflows because it permits unreviewed future releases.
  7. Install the dependency in an isolated virtual environment or restricted container and run it without administrative privileges.
  8. Treat package updates as security-sensitive changes and repeat source, dependency, and artifact review before updating the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

  • current supported range is 5MB to 100MB
  • response may be single or multipart
  • expiresIn refers to the signed uploadUrl or parts[].uploadUrl lifetime only; it does not describe a separate Worker-side upload-session TTL
  • if complete says the upload session was not found, first verify that you are using the exact same id returned by that specific prepare call Single upload response example:
json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to upload and publish files to a public service, yet the top-level description does not clearly warn that resulting links, previews, or sites may be publicly accessible. This can mislead downstream agents or users into sharing sensitive files, folders, or static-site contents externally without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This skill instructs agents to transmit file contents and metadata to an external domain, which is inherently risky because it can exfiltrate sensitive local data outside the current trust boundary. In context, external transmission is the core function of the skill, so the danger comes less from hidden behavior and more from insufficient guardrails around what may be uploaded and when.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

  • other files should use download links

Minimal Prepare Request

bash
curl -X POST "https://www.okfile.com/api/upload/prepare" \
  -H "Content-Type: application/json" \
  --data '{"filename":"photo.jpg","size":12345,"contentType":"image/jpeg","preferredPartSize":5242880}'

Static analysis

No suspicious patterns detected.