Back to skill

Security audit

Api Gateway 1.0.64

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad Maton API gateway for many external services, and it is mostly disclosed, but it exposes high-impact API authority and includes unsafe credential-printing troubleshooting examples.

Review before installing. Use this only if you trust Maton to broker access to your connected services, grant the narrowest OAuth/API scopes possible, and avoid using it for destructive or administrative actions unless you explicitly confirm the target and impact. Do not print, paste, log, or share MATON_API_KEY values, Authorization headers, raw connection responses, or connect.maton.ai session URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:79
Finding

Plaintext Exposure of API Keys and OAuth Connection Session URLs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:79-100, SKILL.md:129-145, and SKILL.md:584-598
Vulnerability Type: Sensitive credential disclosure through terminal and diagnostic output
Risk Level: Medium

Vulnerable Code

The troubleshooting instructions explicitly print the complete Maton API key:

bash
echo $MATON_API_KEY

The connection-management examples print complete API responses without redacting sensitive fields:

python
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections?app=slack&status=ACTIVE')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))

The documented response includes a connection URL containing a session token:

json
{
  "connections": [
    {
      "connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
      "status": "ACTIVE",
      "creation_time": "2025-12-08T07:20:53.488460Z",
      "last_updated_time": "2026-01-31T20:03:32.593153Z",
      "url": "https://connect.maton.ai/?session_token=5e9...",
      "app": "slack",
      "method": "OAUTH2",
      "metadata": {}
    }
  ]
}

A similar unredacted response is printed when retrieving an individual connection:

python
import urllib.request, os, json
req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))

Technical Analysis

MATON_API_KEY is a bearer credential used to authenticate requests to the Maton gateway and connection-management service. Printing its complete value exposes it to terminal scrollback, shell-session recording, CI/CD logs, remote support sessions, agent execution transcripts, screenshots, and copied diagnostic output.

The c ...[truncated 2378 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext API-key command with a presence-only test:

    bash
    if [ -n "${MATON_API_KEY:-}" ]; then
      echo "MATON_API_KEY is configured"
    else
      echo "MATON_API_KEY is not configured"
    fi
    
  2. Never print complete connection-management responses. Extract only non-sensitive fields such as connection ID, application name, and status:

    python
    response = json.load(urllib.request.urlopen(req))
    safe_connections = [
        {
            "connection_id": item.get("connection_id"),
            "app": item.get("app"),
            "status": item.get("status")
        }
        for item in response.get("connections", [])
    ]
    print(json.dumps(safe_connections, indent=2))
    
  3. Redact fields named url, session_token, authorization, token, secret, and api_key before displaying or logging API responses.

  4. Add an explicit warning that users must not paste API keys, connection URLs, authorization headers, or raw connection responses into chats, issue trackers, or support tickets.

  5. Ensure connection session tokens are short-lived, single-use, bound to the initiating user and browser session, and invalidated immediately after successful authorization.

  6. Provide API-key rotation and session-revocation procedures for users who have accidentally exposed diagnostic output.

  7. Apply server-side log redaction to Authorization headers and sensitive URL query parameters across gateway.maton.ai, ctrl.maton.ai, and connect.maton.ai.

Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (481)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 47)May include surrounding context.

Delete Contact

bash
DELETE /active-campaign/api/3/contacts/{contactId}

Tags

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 87)May include surrounding context.

Remove Tag from Contact

bash
DELETE /active-campaign/api/3/contactTags/{contactTagId}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/acuity-scheduling/README.md (reported line 127)May include surrounding context.

Delete Block

bash
DELETE /acuity-scheduling/api/v1/blocks/{id}

List Forms

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/airtable/README.md (reported line 99)May include surrounding context.

Delete Records

bash
DELETE /airtable/v0/{baseId}/{tableIdOrName}?records[]=recXXXXX&records[]=recYYYYY

List Bases

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 64)May include surrounding context.

Delete a Task

bash
DELETE /asana/api/1.0/tasks/{task_gid}

Get Subtasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 134)May include surrounding context.

Delete Webhook

bash
DELETE /asana/api/1.0/webhooks/{webhook_gid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 76)May include surrounding context.

Delete Record

bash
DELETE /attio/v2/objects/{object}/records/{record_id}

List Tasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 144)May include surrounding context.

Delete Note

bash
DELETE /attio/v2/notes/{note_id}

Comments

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 248)May include surrounding context.

Delete List Entry

bash
DELETE /attio/v2/lists/{list}/entries/{entry_id}

Meetings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/baserow/README.md (reported line 57)May include surrounding context.

Delete Row

bash
DELETE /baserow/api/database/rows/table/{table_id}/{row_id}/

Batch Create Rows

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/beehiiv/README.md (reported line 61)May include surrounding context.

Delete Subscription

bash
DELETE /beehiiv/v2/publications/{publication_id}/subscriptions/{subscription_id}

Posts

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 72)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 73)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Get File

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 98)May include surrounding context.

Delete File

bash
DELETE /box/2.0/files/{file_id}

Create Shared Link

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 141)May include surrounding context.

Trash

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 142)May include surrounding context.

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Collections

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 160)May include surrounding context.

bash
GET /box/2.0/webhooks
POST /box/2.0/webhooks
DELETE /box/2.0/webhooks/{webhook_id}

Pagination

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/brevo/README.md (reported line 56)May include surrounding context.

Delete Contact

bash
DELETE /brevo/v3/contacts/{identifier}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 50)May include surrounding context.

Delete Event Type

bash
DELETE /cal-com/v2/event-types/{eventTypeId}

Event Type Webhooks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 77)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/event-types/{eventTypeId}/webhooks/{webhookId}

Bookings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 130)May include surrounding context.

Delete Schedule

bash
DELETE /cal-com/v2/schedules/{scheduleId}

Availability Slots

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 188)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/webhooks/{webhookId}

Teams

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/calendly/README.md (reported line 89)May include surrounding context.

Delete Webhook Subscription

bash
DELETE /calendly/webhook_subscriptions/{uuid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/callrail/README.md (reported line 120)May include surrounding context.

Delete Tag

bash
DELETE /callrail/v3/a/{account_id}/tags/{tag_id}.json

Users

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/clickfunnels/README.md (reported line 88)May include surrounding context.

Delete Contact

bash
DELETE /clickfunnels/api/v2/contacts/{contact_id}

Upsert Contact

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete Google Sheets spreadsheet ID instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:485

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:94