T09 · Insecure Skill Coding Practices
- Location
SKILL.md:584- Finding
Bearer API Key Disclosure Through Troubleshooting Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:584-588
Vulnerability Type: Credential exposure through insecure diagnostic output
Risk Level: MediumVulnerable Code
bash 1. Check that the `MATON_API_KEY` environment variable is set: echo $MATON_API_KEYTechnical Analysis
The troubleshooting procedure prints the complete
MATON_API_KEYbearer credential to standard output. Although checking whether the environment variable exists is legitimate, disclosing its value is unnecessary.Terminal output may be retained in agent transcripts, CI/CD logs, shell-session recordings, support bundles, screen-sharing recordings, or other monitoring systems. Anyone who can access such output may recover the credential. The surrounding Skill documentation shows that this key is accepted in the
Authorizationheader by Maton gateway and connection-management endpoints.Attack Path
- A user encounters an authentication problem and follows the documented troubleshooting procedure.
echo $MATON_API_KEYprints the complete bearer key.- The output is retained in a transcript, log, recording, screenshot, or support message accessible to another party.
- That party extracts the key.
- The exposed key is submitted as a bearer credential to Maton gateway or control endpoints.
- If the key remains valid, the party can perform operations available through the victim's authorized Maton connections.
Impact Assessment
Successful exploitation may permit authentication to Maton under the affected account. The resulting scope depends on the third-party connections and OAuth permissions that the user previously authorized. Potentially exposed capabilities include reading third-party data, creating or modifying records, sending communications, and invoking documented destructive methods such as deletion.
The Maton key does not independently create third-party authorization, so exploitation remains ...[truncated 185 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the value-printing command with a non-disclosing presence check:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiAdditional hardening measures:
- Explicitly instruct users never to print, log, paste, or share the API key.
- Redact Authorization headers and secret environment variables from agent transcripts, CI logs, telemetry, and support bundles.
- Add a documented key-revocation and rotation procedure.
- Advise users to rotate the key immediately if it has appeared in retained output.
- Where supported, use short-lived, narrowly scoped credentials rather than a reusable account-level bearer key.
- Ensure gateway and control-plane logs never retain complete bearer credentials.
