T09 · Insecure Skill Coding Practices
- Location
SKILL.md:79- Finding
Plaintext Exposure of API Keys and OAuth Connection Session URLs
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:79-100,SKILL.md:129-145, andSKILL.md:584-598
Vulnerability Type: Sensitive credential disclosure through terminal and diagnostic output
Risk Level: MediumVulnerable Code
The troubleshooting instructions explicitly print the complete Maton API key:
bash echo $MATON_API_KEYThe connection-management examples print complete API responses without redacting sensitive fields:
python import urllib.request, os, json req = urllib.request.Request('https://ctrl.maton.ai/connections?app=slack&status=ACTIVE') req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}') print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))The documented response includes a connection URL containing a session token:
json { "connections": [ { "connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80", "status": "ACTIVE", "creation_time": "2025-12-08T07:20:53.488460Z", "last_updated_time": "2026-01-31T20:03:32.593153Z", "url": "https://connect.maton.ai/?session_token=5e9...", "app": "slack", "method": "OAUTH2", "metadata": {} } ] }A similar unredacted response is printed when retrieving an individual connection:
python import urllib.request, os, json req = urllib.request.Request('https://ctrl.maton.ai/connections/{connection_id}') req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}') print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))Technical Analysis
MATON_API_KEYis a bearer credential used to authenticate requests to the Maton gateway and connection-management service. Printing its complete value exposes it to terminal scrollback, shell-session recording, CI/CD logs, remote support sessions, agent execution transcripts, screenshots, and copied diagnostic output.The c ...[truncated 2378 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the plaintext API-key command with a presence-only test:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is configured" else echo "MATON_API_KEY is not configured" fi -
Never print complete connection-management responses. Extract only non-sensitive fields such as connection ID, application name, and status:
python response = json.load(urllib.request.urlopen(req)) safe_connections = [ { "connection_id": item.get("connection_id"), "app": item.get("app"), "status": item.get("status") } for item in response.get("connections", []) ] print(json.dumps(safe_connections, indent=2)) -
Redact fields named
url,session_token,authorization,token,secret, andapi_keybefore displaying or logging API responses. -
Add an explicit warning that users must not paste API keys, connection URLs, authorization headers, or raw connection responses into chats, issue trackers, or support tickets.
-
Ensure connection session tokens are short-lived, single-use, bound to the initiating user and browser session, and invalidated immediately after successful authorization.
-
Provide API-key rotation and session-revocation procedures for users who have accidentally exposed diagnostic output.
-
Apply server-side log redaction to
Authorizationheaders and sensitive URL query parameters acrossgateway.maton.ai,ctrl.maton.ai, andconnect.maton.ai.
-
