T09 · Insecure Skill Coding Practices
- Location
SKILL.md:594- Finding
Full Maton API Key Disclosed by Troubleshooting Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 594-600
Vulnerability Type: Exposure of a bearer credential through terminal output
Risk Level: MediumVulnerable Code
markdown ### Troubleshooting: API Key Issues 1. Check that the `MATON_API_KEY` environment variable is set: ```bash echo $MATON_API_KEYtext ### Technical Analysis The troubleshooting procedure instructs users to print the complete `MATON_API_KEY` value. This is a reusable bearer credential used to authenticate requests to Maton-controlled gateway and connection-management endpoints. Printing the key can expose it through shell history or transcripts, agent conversation logs, CI/CD output, terminal recording, screen sharing, support bundles, or copied diagnostic output. Bearer credentials do not require additional proof of possession, so an observer who captures the value may reuse it directly. The gateway architecture and transmission of service data through Maton are explicitly declared and necessary for the Skill's managed-OAuth functionality. The vulnerability is not the use of the gateway itself, but the unnecessary disclosure of the complete gateway credential during troubleshooting. ### Attack Path 1. A user encounters an authentication problem and follows the documented troubleshooting procedure. 2. The user executes `echo $MATON_API_KEY`. 3. The complete bearer credential appears in terminal output. 4. The output is retained in an agent transcript, terminal recording, CI log, support report, screenshot, or another observable channel. 5. An attacker obtains the exposed value. 6. The attacker supplies it as `Authorization: Bearer <stolen-key>` to `gateway.maton.ai` or `ctrl.maton.ai`. 7. If the key remains valid, the attacker can interact with resources available through the victim's active Maton connections. ### Impact Assessment A stolen key could allow unauthorized use of the victim's Maton ...[truncated 587 chars]- Remediation
View remediation
Remediation Suggestions
Replace the command with a presence check that never reveals the value:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiAdditional hardening measures:
- Explicitly warn users never to print, paste, log, or include the key in support requests.
- Redact bearer tokens from application, gateway, CI/CD, and agent logs.
- Provide a server-side credential-validation endpoint or command that returns only validity status and non-sensitive metadata.
- Use short-lived or narrowly scoped credentials where supported.
- Document immediate key revocation and rotation procedures for suspected exposure.
- Review existing transcripts and diagnostic logs for previously disclosed keys and rotate any affected credentials.
