T09 · Insecure Skill Coding Practices
- Location
SKILL.md:601- Finding
API Key Disclosure Through Troubleshooting Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 601-605
Vulnerability Type: Secret exposure through terminal output
Risk Level: MediumComplete Vulnerable Code Snippet:
markdown 1. Check that the `MATON_API_KEY` environment variable is set: ```bash echo $MATON_API_KEYtext ### Technical Analysis The troubleshooting instructions print the complete value of `MATON_API_KEY` to standard output. This exceeds what is necessary to determine whether the environment variable is configured. Terminal output may be exposed through screen sharing, shell-session recording, CI/CD logs, support transcripts, agent execution traces, or shoulder surfing. Although the rest of the Skill appropriately reads the key from the environment and sends it over HTTPS to the documented Maton services, displaying the raw credential creates an avoidable disclosure channel. The Skill documents use of this bearer credential with `gateway.maton.ai` and `ctrl.maton.ai`. Therefore, a disclosed key could be replayed against the operations authorized for the associated Maton account. ### Attack Path 1. A user encounters an authentication problem and follows the documented troubleshooting procedure. 2. The command `echo $MATON_API_KEY` prints the complete bearer credential. 3. The output is retained in a log or transcript, shown during screen sharing, or observed by another party. 4. An attacker extracts the exposed credential. 5. The attacker supplies it in an `Authorization: Bearer` header to the documented Maton endpoints. 6. Subject to the account's server-side permissions and active OAuth connections, the attacker can invoke available connection-management or WhatsApp gateway operations. ### Impact Assessment Successful exploitation exposes the privileges associated with the affected Maton API key. Based on the documented API surface, this may permit unauthorized WhatsApp message operations, access to connecti ...[truncated 347 chars]- Remediation
View remediation
Remediation Suggestions
Replace the secret-printing command with a presence check that never reveals the value:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiAdditional hardening measures:
- Explicitly warn users never to print, paste, log, or share the API key.
- Redact authorization headers and credentials from agent transcripts, debug output, and CI/CD logs.
- Provide documented revocation and rotation procedures for keys that may have been disclosed.
- Apply server-side least privilege, expiration, rate limits, and endpoint restrictions to API keys where supported.
- Monitor for anomalous gateway and connection-management activity associated with exposed credentials.
