Back to skill

Security audit

OpenAi Berto

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate WhatsApp Business API guide, but it enables customer messaging and destructive business actions with weak safety guidance around confirmation and API-key handling.

Review this before installing if you will let an agent act with real WhatsApp Business access. Use a least-privilege Maton key, avoid printing or sharing MATON_API_KEY, specify the intended Maton connection when multiple accounts exist, and require explicit confirmation before sending customer messages, updating profiles, or deleting connections, media, or templates.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:601
Finding

API Key Disclosure Through Troubleshooting Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 601-605
Vulnerability Type: Secret exposure through terminal output
Risk Level: Medium

Complete Vulnerable Code Snippet:

markdown
1. Check that the `MATON_API_KEY` environment variable is set:

```bash
echo $MATON_API_KEY
text

### Technical Analysis

The troubleshooting instructions print the complete value of `MATON_API_KEY` to standard output. This exceeds what is necessary to determine whether the environment variable is configured.

Terminal output may be exposed through screen sharing, shell-session recording, CI/CD logs, support transcripts, agent execution traces, or shoulder surfing. Although the rest of the Skill appropriately reads the key from the environment and sends it over HTTPS to the documented Maton services, displaying the raw credential creates an avoidable disclosure channel.

The Skill documents use of this bearer credential with `gateway.maton.ai` and `ctrl.maton.ai`. Therefore, a disclosed key could be replayed against the operations authorized for the associated Maton account.

### Attack Path

1. A user encounters an authentication problem and follows the documented troubleshooting procedure.
2. The command `echo $MATON_API_KEY` prints the complete bearer credential.
3. The output is retained in a log or transcript, shown during screen sharing, or observed by another party.
4. An attacker extracts the exposed credential.
5. The attacker supplies it in an `Authorization: Bearer` header to the documented Maton endpoints.
6. Subject to the account's server-side permissions and active OAuth connections, the attacker can invoke available connection-management or WhatsApp gateway operations.

### Impact Assessment

Successful exploitation exposes the privileges associated with the affected Maton API key. Based on the documented API surface, this may permit unauthorized WhatsApp message operations, access to connecti
...[truncated 347 chars]
Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a presence check that never reveals the value:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Additional hardening measures:

  1. Explicitly warn users never to print, paste, log, or share the API key.
  2. Redact authorization headers and credentials from agent transcripts, debug output, and CI/CD logs.
  3. Provide documented revocation and rotation procedures for keys that may have been disclosed.
  4. Apply server-side least privilege, expiration, rate limits, and endpoint restrictions to API keys where supported.
  5. Monitor for anomalous gateway and connection-management activity associated with exposed credentials.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes a destructive delete-media operation with no guardrails, ownership checks, or confirmation guidance. In an agent context, attacker-influenced parameters or ambiguous prompts could cause unintended deletion of business assets or evidence needed for audits and customer support.

Content

Scanner excerpt · SKILL.md (reported line 398)May include surrounding context.

Delete Media

bash
DELETE /whatsapp-business/v21.0/{media_id}

Message Templates

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deleting message templates is a high-impact administrative action because templates may be required for business workflows, notifications, and compliance-sensitive communications. The documentation presents the operation without safety checks, making prompt-driven misuse or mistaken parameter selection more dangerous in an autonomous agent setting.

Content

Scanner excerpt · SKILL.md (reported line 446)May include surrounding context.

Delete Template

bash
DELETE /whatsapp-business/v21.0/{whatsapp_business_account_id}/message_templates?name=template_name

Phone Numbers

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill prominently documents actions that send outbound WhatsApp messages and delete resources, but it does not clearly require explicit user confirmation before performing irreversible or externally visible operations. In an agent setting, this can cause unintended customer contact, data deletion, or business-impacting actions if user intent is ambiguous or prompts are manipulated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 499)May include surrounding context.

md
};

// Send text message
await fetch(
  'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
  {
    method: 'POST',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 514)May include surrounding context.

md
};

// Send text message
await fetch(
  'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
  {
    method: 'POST',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 544)May include surrounding context.

md
}

# Send text message
response = requests.post(
    'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
    headers=headers,
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 556)May include surrounding context.

md
}

# Send text message
response = requests.post(
    'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
    headers=headers,
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 544)May include surrounding context.

md
}

# Send text message
response = requests.post(
    'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
    headers=headers,
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 556)May include surrounding context.

md
}

# Send text message
response = requests.post(
    'https://gateway.maton.ai/whatsapp-business/v21.0/PHONE_NUMBER_ID/messages',
    headers=headers,
    json={

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The documentation includes natural-language configuration that fixes template language to en_US in examples, and similar English-only locale values recur later. Because the skill does not state that English is merely an example or offer user choice, it can be read as prescribing a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:105