Back to skill

Security audit

19 API Gateway

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed API gateway skill, but it gives broad read/write/delete authority across many connected services and includes an unsafe troubleshooting command that can reveal the API key.

Install only if you are comfortable letting an agent make direct native API calls against your Maton-connected services. Use narrowly scoped third-party connections where possible, confirm destructive or public-posting actions manually, avoid granting access to financial/admin accounts unless needed, and do not print or paste MATON_API_KEY; rotate it if it has appeared in logs or transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:584
Finding

Bearer API Key Disclosure Through Troubleshooting Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:584-588
Vulnerability Type: Credential exposure through insecure diagnostic output
Risk Level: Medium

Vulnerable Code

bash
1. Check that the `MATON_API_KEY` environment variable is set:

echo $MATON_API_KEY

Technical Analysis

The troubleshooting procedure prints the complete MATON_API_KEY bearer credential to standard output. Although checking whether the environment variable exists is legitimate, disclosing its value is unnecessary.

Terminal output may be retained in agent transcripts, CI/CD logs, shell-session recordings, support bundles, screen-sharing recordings, or other monitoring systems. Anyone who can access such output may recover the credential. The surrounding Skill documentation shows that this key is accepted in the Authorization header by Maton gateway and connection-management endpoints.

Attack Path

  1. A user encounters an authentication problem and follows the documented troubleshooting procedure.
  2. echo $MATON_API_KEY prints the complete bearer key.
  3. The output is retained in a transcript, log, recording, screenshot, or support message accessible to another party.
  4. That party extracts the key.
  5. The exposed key is submitted as a bearer credential to Maton gateway or control endpoints.
  6. If the key remains valid, the party can perform operations available through the victim's authorized Maton connections.

Impact Assessment

Successful exploitation may permit authentication to Maton under the affected account. The resulting scope depends on the third-party connections and OAuth permissions that the user previously authorized. Potentially exposed capabilities include reading third-party data, creating or modifying records, sending communications, and invoking documented destructive methods such as deletion.

The Maton key does not independently create third-party authorization, so exploitation remains ...[truncated 185 chars]

Remediation
View remediation

Remediation Suggestions

Replace the value-printing command with a non-disclosing presence check:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Additional hardening measures:

  1. Explicitly instruct users never to print, log, paste, or share the API key.
  2. Redact Authorization headers and secret environment variables from agent transcripts, CI logs, telemetry, and support bundles.
  3. Add a documented key-revocation and rotation procedure.
  4. Advise users to rotate the key immediately if it has appeared in retained output.
  5. Where supported, use short-lived, narrowly scoped credentials rather than a reusable account-level bearer key.
  6. Ensure gateway and control-plane logs never retain complete bearer credentials.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (497)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 47)May include surrounding context.

Delete Contact

bash
DELETE /active-campaign/api/3/contacts/{contactId}

Tags

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 87)May include surrounding context.

Remove Tag from Contact

bash
DELETE /active-campaign/api/3/contactTags/{contactTagId}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/acuity-scheduling/README.md (reported line 127)May include surrounding context.

Delete Block

bash
DELETE /acuity-scheduling/api/v1/blocks/{id}

List Forms

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/airtable/README.md (reported line 99)May include surrounding context.

Delete Records

bash
DELETE /airtable/v0/{baseId}/{tableIdOrName}?records[]=recXXXXX&records[]=recYYYYY

List Bases

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 64)May include surrounding context.

Delete a Task

bash
DELETE /asana/api/1.0/tasks/{task_gid}

Get Subtasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 134)May include surrounding context.

Delete Webhook

bash
DELETE /asana/api/1.0/webhooks/{webhook_gid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 76)May include surrounding context.

Delete Record

bash
DELETE /attio/v2/objects/{object}/records/{record_id}

List Tasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 144)May include surrounding context.

Delete Note

bash
DELETE /attio/v2/notes/{note_id}

Comments

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 248)May include surrounding context.

Delete List Entry

bash
DELETE /attio/v2/lists/{list}/entries/{entry_id}

Meetings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/baserow/README.md (reported line 57)May include surrounding context.

Delete Row

bash
DELETE /baserow/api/database/rows/table/{table_id}/{row_id}/

Batch Create Rows

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/beehiiv/README.md (reported line 61)May include surrounding context.

Delete Subscription

bash
DELETE /beehiiv/v2/publications/{publication_id}/subscriptions/{subscription_id}

Posts

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 72)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 73)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Get File

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 98)May include surrounding context.

Delete File

bash
DELETE /box/2.0/files/{file_id}

Create Shared Link

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 141)May include surrounding context.

Trash

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 142)May include surrounding context.

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Collections

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 160)May include surrounding context.

bash
GET /box/2.0/webhooks
POST /box/2.0/webhooks
DELETE /box/2.0/webhooks/{webhook_id}

Pagination

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/brevo/README.md (reported line 56)May include surrounding context.

Delete Contact

bash
DELETE /brevo/v3/contacts/{identifier}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 50)May include surrounding context.

Delete Event Type

bash
DELETE /cal-com/v2/event-types/{eventTypeId}

Event Type Webhooks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 77)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/event-types/{eventTypeId}/webhooks/{webhookId}

Bookings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 130)May include surrounding context.

Delete Schedule

bash
DELETE /cal-com/v2/schedules/{scheduleId}

Availability Slots

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 188)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/webhooks/{webhookId}

Teams

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/calendly/README.md (reported line 89)May include surrounding context.

Delete Webhook Subscription

bash
DELETE /calendly/webhook_subscriptions/{uuid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/callrail/README.md (reported line 120)May include surrounding context.

Delete Tag

bash
DELETE /callrail/v3/a/{account_id}/tags/{tag_id}.json

Users

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The documented DELETE contact endpoint enables irreversible or hard-to-recover removal of contact records if an agent is induced to supply an attacker-chosen contact_id. Because this skill operates against user-authorized third-party accounts, parameter abuse could delete CRM/marketing data, disrupt campaigns, or remove audit-relevant customer records.

Content

Scanner excerpt · references/clickfunnels/README.md (reported line 88)May include surrounding context.

Delete Contact

bash
DELETE /clickfunnels/api/v2/contacts/{contact_id}

Upsert Contact

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete Google Sheets spreadsheet ID instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:485

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:94