Back to skill

Security audit

Coda

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Coda integration that uses Maton OAuth/API access to read and manage Coda content with explicit cautions for credentials and writes.

Before installing, understand that this can access and modify data in the connected Coda account through Maton. Prefer OAuth, choose the narrowest Coda scopes available, pin the intended connection when multiple accounts exist, and require explicit confirmation before any create, update, delete, sharing, or permission change.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.