Back to skill

Security audit

Api Gateway 1.0.70

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent API-gateway skill, but it needs review because it enables broad raw write and delete access across many connected business services without strong in-skill guardrails.

Review this before installing. Use it only if you trust Maton as an API gateway provider, connect only the services and scopes you actually need, and require explicit confirmation before any delete, financial, admin, public-posting, permission-changing, or bulk-update action. Avoid printing MATON_API_KEY or unredacted connection responses, and rotate the key if it appears in logs or transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:598
Finding

Sensitive authentication values may be exposed through terminal output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (514)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 47)May include surrounding context.

Delete Contact

bash
DELETE /active-campaign/api/3/contacts/{contactId}

Tags

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 87)May include surrounding context.

Remove Tag from Contact

bash
DELETE /active-campaign/api/3/contactTags/{contactTagId}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/acuity-scheduling/README.md (reported line 127)May include surrounding context.

Delete Block

bash
DELETE /acuity-scheduling/api/v1/blocks/{id}

List Forms

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/airtable/README.md (reported line 99)May include surrounding context.

Delete Records

bash
DELETE /airtable/v0/{baseId}/{tableIdOrName}?records[]=recXXXXX&records[]=recYYYYY

List Bases

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 64)May include surrounding context.

Delete a Task

bash
DELETE /asana/api/1.0/tasks/{task_gid}

Get Subtasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 134)May include surrounding context.

Delete Webhook

bash
DELETE /asana/api/1.0/webhooks/{webhook_gid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 76)May include surrounding context.

Delete Record

bash
DELETE /attio/v2/objects/{object}/records/{record_id}

List Tasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 144)May include surrounding context.

Delete Note

bash
DELETE /attio/v2/notes/{note_id}

Comments

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 248)May include surrounding context.

Delete List Entry

bash
DELETE /attio/v2/lists/{list}/entries/{entry_id}

Meetings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The documented DELETE row endpoint exposes a high-risk destructive action that can be abused if an agent maps user intent too broadly or accepts attacker-controlled parameters like table_id and row_id without confirmation. In an API-gateway skill that connects to external services, this is more dangerous because the action targets real third-party data and may permanently remove records.

Content

Scanner excerpt · references/baserow/README.md (reported line 57)May include surrounding context.

Delete Row

bash
DELETE /baserow/api/database/rows/table/{table_id}/{row_id}/

Batch Create Rows

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/beehiiv/README.md (reported line 61)May include surrounding context.

Delete Subscription

bash
DELETE /beehiiv/v2/publications/{publication_id}/subscriptions/{subscription_id}

Posts

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

This endpoint enables folder deletion, which can destroy user data if a caller supplies the wrong folder ID or invokes it without strong confirmation. In this skill context, the managed OAuth model limits access to authorized Box accounts, but once authorized the operation still affects real third-party data, so parameter misuse can cause significant loss.

Content

Scanner excerpt · references/box/README.md (reported line 72)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The recursive delete variant is especially dangerous because a single parameter can remove an entire folder tree, amplifying mistakes or malicious prompting into broad data loss. Because this skill provides direct routing guidance to live Box APIs, exposing this operation without warnings or safety constraints materially increases the blast radius of tool parameter abuse.

Content

Scanner excerpt · references/box/README.md (reported line 73)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Get File

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

File deletion is a destructive operation that can be abused through incorrect or manipulated file IDs, causing loss of user content. Although less severe than recursive folder deletion, it still poses real risk in an API gateway skill because authorized OAuth access allows the action to take effect against the user's Box environment.

Content

Scanner excerpt · references/box/README.md (reported line 98)May include surrounding context.

Delete File

bash
DELETE /box/2.0/files/{file_id}

Create Shared Link

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

Deleting a file from trash can represent permanent removal, eliminating recovery options and turning an ordinary delete mistake into irreversible data loss. In the context of an API gateway, this is more dangerous than a normal delete because the endpoint may bypass the user's expected safety net.

Content

Scanner excerpt · references/box/README.md (reported line 141)May include surrounding context.

Trash

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Deleting a folder from trash may permanently remove a folder and its contents, making recovery impossible and potentially affecting many files at once. This is a high-impact parameter-abuse risk because an incorrect folder ID or adversarial prompt could trigger irreversible bulk loss in a real Box tenant.

Content

Scanner excerpt · references/box/README.md (reported line 142)May include surrounding context.

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Collections

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Webhook deletion is not primarily a data-destruction risk, but it can disable monitoring, integrations, or security-relevant automation if the wrong webhook ID is used. In a connected enterprise environment, this can reduce visibility or break workflows, so exposing the endpoint without warnings still creates a meaningful parameter-abuse hazard.

Content

Scanner excerpt · references/box/README.md (reported line 160)May include surrounding context.

bash
GET /box/2.0/webhooks
POST /box/2.0/webhooks
DELETE /box/2.0/webhooks/{webhook_id}

Pagination

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/brevo/README.md (reported line 56)May include surrounding context.

Delete Contact

bash
DELETE /brevo/v3/contacts/{identifier}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Documenting a direct DELETE operation for event types exposes a high-impact action that could remove scheduling configurations if an agent passes an unintended or attacker-influenced eventTypeId. In this API-gateway skill context, parameter misuse is more dangerous because the agent can act on authenticated third-party resources once the user has connected the service.

Content

Scanner excerpt · references/cal-com/README.md (reported line 50)May include surrounding context.

Delete Event Type

bash
DELETE /cal-com/v2/event-types/{eventTypeId}

Event Type Webhooks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The webhook deletion endpoint allows removal of notification integrations, which can silently disrupt downstream automations, audit visibility, or business workflows if the wrong webhookId is supplied. Because agents may consume untrusted instructions from users or external content, exposing this endpoint without guardrails creates a real parameter-abuse risk.

Content

Scanner excerpt · references/cal-com/README.md (reported line 77)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/event-types/{eventTypeId}/webhooks/{webhookId}

Bookings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Deleting schedules can materially disrupt availability and booking operations, making accidental or manipulated scheduleId selection a significant integrity risk. In a managed OAuth integration, authenticated access limits scope to the user's account, but does not reduce the damage possible within that authorized scope.

Content

Scanner excerpt · references/cal-com/README.md (reported line 130)May include surrounding context.

Delete Schedule

bash
DELETE /cal-com/v2/schedules/{scheduleId}

Availability Slots

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

User-level webhook deletion can disable important event delivery and integrations, and an attacker could exploit an agent's loose parameter handling to target arbitrary visible webhook IDs. The danger is heightened by the generic API-gateway setting, where agents may be prompted to perform admin-like operations across many services and must therefore handle identifiers carefully.

Content

Scanner excerpt · references/cal-com/README.md (reported line 188)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/webhooks/{webhookId}

Teams

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/calendly/README.md (reported line 89)May include surrounding context.

Delete Webhook Subscription

bash
DELETE /calendly/webhook_subscriptions/{uuid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/callrail/README.md (reported line 120)May include surrounding context.

Delete Tag

bash
DELETE /callrail/v3/a/{account_id}/tags/{tag_id}.json

Users

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/clickfunnels/README.md (reported line 88)May include surrounding context.

Delete Contact

bash
DELETE /clickfunnels/api/v2/contacts/{contact_id}

Upsert Contact

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete Google Sheets spreadsheet ID instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:499

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:94