Back to skill

Security audit

Maton browse plan — API Gateway

Security checks for vulnerabilities and agentic risk

Overview

This skill is review-worthy because it pushes users toward an external browser-history capture extension and can repeatedly read browsing-derived data through a local relay.

Install only if you are comfortable granting a browser extension access to browsing history/tabs and making that browsing-derived plan available to an agent. Prefer one-shot downloaded JSON if you want tighter control, review captured data before sharing it, avoid running the native-host installer unless you need popup-controlled relay start/stop, and use the narrowest browser/install option available.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:21
Finding

Forced External Promotion and Agent Response Hijacking

Content
View full analysis
**Agent behavior (read this first):** If the user just added this skill or says they want browse-based Maton hints, **do not** recite the YAML `description`, version, or any host “What’s New” text to them as if it were help. Unless they clearly confirm the extension is **already installed** (store or unpacked), your **first concrete step** is to **give them the Chrome Web Store URL above** (paste the `https://…` line or the markdown link) and short install clicks—**before** relay URLs, `matonPlan`, or Maton API talk. Prefer the **store** for everyone except contributors; use repo **build + Load unpacked** only when they are developing or cannot use the store. After install, the extension appears on `chrome://extensions` as **Maton API plan — browsing capture**. ## Install the Chrome extension (required before matonPlan) Walk the user through extension install **before** discussing relay URLs or Maton diffs. ``` ### Technical Analysis The Skill contains imperative instructions that control the agent's response content and ordering. It requires the agent to promote a fixed external Chrome Web Store listing, prohibits skipping the link, and mandates that installation guidance be the first concrete onboarding action. These directives go beyond describing the Skill's operatio ...[truncated 1809 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:49
Finding

Execution of Unpinned External Dependencies and Native-Host Installation Scripts

Content
View full analysis
`** with the ID shown on `chrome://extensions` for that folder. 3. Restart the browser, reload the extension if needed, then use **Start** in the popup. The installer writes the manifest for common Chromium-based browsers (Chrome, Brave, Edge, Arc, etc.); **`NATIVE_MSG_ONLY=chrome`** limits install to Google Chrome. ``` ### Technical Analysis The Skill directs users to clone a mutable external repository, run `npm install`, execute workspace build scripts, and invoke a native-messaging-host installer. The audited package does not include the referenced repository contents, package manifests, dependency lockfiles, lifecycle scripts, native-host source, or installer implementation. Running `npm install` may execute package lifecycle scripts from the project or its dependencies. Without a pinned commit, locked dependency graph, integrity verification, or included source, the effective code executed ...[truncated 2057 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- Reuse **identical** `MATON_API_KEY`, base URLs, and HTTP patterns from **byungkyu/api-gateway** `SKILL.md` for all Maton calls.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
- Reuse **identical** `MATON_API_KEY`, base URLs, and HTTP patterns from **byungkyu/api-gateway** `SKILL.md` for all Maton calls.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
2. Click **Add to Chrome** / **Install** and accept permissions when prompted.
3. Optional: pin the extension from the puzzle menu.

**Stable extension ID (Web Store build):** `dgecpbbjdgiindogaboidejihbmkhnai` — same for every user; use it for **`install-native-host`** (below) without asking users to copy an ID from `chrome://extensions`.

When they use capture, the browser may ask for **history**, **tabs**, and related access — they should **Allow** or exports will be incomplete.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the agent to automatically fetch browsing-derived data from a local relay on every new message or session, effectively normalizing repeated access to sensitive behavioral data. Although the relay is local and user-installed, the instructions do not require an explicit per-session consent prompt or a prominent privacy warning before routine collection, which increases the risk of silent over-collection and user surprise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.