Back to skill

Security audit

API Gateway

Security checks for vulnerabilities and agentic risk

Overview

This is a broad but clearly disclosed API gateway skill for user-connected services, with sensitive actions mostly governed by explicit confirmation and least-privilege instructions.

Install only if you trust Maton and intend to let an agent call APIs for services you have connected. Before approving actions, verify the exact connected account, target resource, recipients, data being sent or retrieved, and whether the action creates persistent forwarding, automation, hosted code, or irreversible deletion. Avoid broad OAuth scopes and delete unused connections, destinations, and functions when the task is finished.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The appointments listing example and response include names, phone numbers, email addresses, and scheduling details, but the markdown does not warn users that these requests may reveal sensitive personal data. Under the markdown-file criteria, skills should disclose behaviors that could affect user privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Clients API examples show retrieval of names, email addresses, phone numbers, and notes, but there is no accompanying warning about handling client records or privacy implications. For markdown files, omission of warnings about user-data-affecting behavior is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete webhook example performs a persistent configuration change that can silently disable event delivery to an external destination, but the section lacks the same explicit confirmation and warning language used for webhook creation. In this skill, webhook subscriptions forward future scheduling events containing personal data, so deleting one can break integrations, audit flows, or compliance-related processing if executed on ambiguous or unverified user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Although L005 provides a general confirmation requirement for write operations, this README does not specifically warn that several documented actions can send communications to recipients or upload contact data, which can affect user privacy and have irreversible external effects. For markdown files, the skill description should clearly disclose behaviors that could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The permanently delete member operation is materially riskier than a normal archive/delete because it irreversibly removes a contact and can affect compliance records, recovery options, and customer data integrity. Although the file has a general write-confirmation policy, this specific endpoint lacks an explicit, local warning about irreversibility, making it easier for an agent or user to treat it like a routine write and execute destructive action without adequate confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Scheduling a campaign is not just a metadata update; it causes future real email delivery to a potentially large audience and can be easy to overlook because the send occurs later. Unlike the adjacent send operation, this section lacks a strong warning to verify campaign identity, recipient scope, send time, and explicit approval, increasing the chance of accidental mass outbound email.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Starting an automation activates outbound email workflows that may immediately or subsequently send messages to many recipients based on existing triggers and queue state. Without an explicit warning, an agent may underestimate this as a harmless state toggle rather than a potentially broad email-sending action with reputational and compliance consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Queueing a subscriber into an automation can trigger real automated email sends to a specific individual, potentially without their current consent context being rechecked. The lack of a local warning obscures that this is an externally impactful action, not a benign queue-management step, and can lead to unauthorized or accidental customer contact.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README claims gateway-injected credentials are never carried in requests, but the included example response exposes a PostHog project api_token (phc_XXX). Even if redacted in the example, documenting and surfacing credential-bearing fields without stronger warnings can normalize handling secrets in responses and may lead agents or users to display, log, or forward live tokens from real API results.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest frames this skill primarily as a gateway for calling connected third-party APIs, with read/list as the default and writes requiring explicit user confirmation. This schema exposes a permanently destructive mailbox operation, which goes beyond the manifest's baseline expectation of routine API reads and introduces a higher-risk behavior that should be tightly constrained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples for sendMessage/sendPhoto/sendDocument/sendVideo/sendAudio/sendLocation/sendContact/sendPoll/sendDice show outbound delivery actions without consistently warning that user-provided or retrieved content will be disclosed into a Telegram chat visible to that chat’s members. In this skill, write operations already require explicit confirmation, but missing per-operation disclosure guidance increases the chance an agent forwards sensitive data, uploads third-party content, or messages the wrong audience without clearly informing the user of the privacy consequence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README documents creating a Twilio Address resource using real-world street, city, postal code, and customer name fields, but unlike other sensitive or destructive operations it provides no privacy or confirmation warning. In this skill context, that omission increases the chance an agent will collect, transmit, or echo personally identifiable information to a live third-party account without adequate minimization or explicit user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README exposes read endpoints for lead records that contain third-party personal data such as name, email, phone number, and submitter IP, but it does not pair those read operations with handling guidance comparable to the write-path warning. That omission increases the chance an agent will retrieve, echo, summarize too specifically, or further process personal data without minimization or redisclosure safeguards, especially because lead reads are framed as ordinary list/get calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The command and profile mutation examples (setMyCommands, deleteMyCommands, setMyDescription, setMyName) omit warnings that these changes persist beyond the current session and alter the bot’s public behavior or presentation for all users interacting with it. While lower impact than data exfiltration, this can still cause unauthorized or accidental operational changes, confusion, or reputational harm if an agent performs these writes without clearly communicating their persistent effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.