Back to skill

Security audit

Jira API工具

Security checks for vulnerabilities and agentic risk

Overview

This Jira skill is not clearly malicious, but it asks for broad Jira-changing power and credential use without enough safeguards.

Review before installing. Use a least-privilege Maton/Jira token, avoid bulk or delete/close operations unless you explicitly approve them, and never print or paste MATON_API_KEY into logs or chats. Treat the Maton API calls as expected for this skill, but keep Jira write permissions narrow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:153
Finding

API Key Exposed Through Terminal Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 153–156
Vulnerability Type: Sensitive credential exposure
Risk Level: Medium

Vulnerable Code

markdown
1. Check that the `MATON_API_KEY` environment variable is set:

```bash
echo $MATON_API_KEY
text

### Technical Analysis

The troubleshooting instructions print the complete `MATON_API_KEY` value to standard output. The stated diagnostic purpose is only to determine whether the environment variable is configured, which does not require disclosure of its contents.

Terminal output may be retained in AI-agent transcripts, CI/CD logs, shell recordings, screenshots, telemetry, or support tickets. Because the same key is used as a bearer credential for requests to `api.maton.ai`, possession of the exposed value may be sufficient to impersonate its owner within the key's authorized scope.

This behavior exceeds the minimum privilege and disclosure necessary for configuration validation. It is classified as `T09: Insecure Skill Coding Practices` because the Skill directly recommends an unsafe secret-handling practice.

### Attack Path

1. A user encounters an authentication or connection error.
2. The user follows the documented troubleshooting procedure.
3. `echo $MATON_API_KEY` writes the complete credential to terminal output.
4. The output is retained in an agent transcript, build log, shell recording, screenshot, or support artifact.
5. An unauthorized party with access to that artifact extracts the API key.
6. The party submits the key as a bearer credential to Maton API endpoints.
7. If the key remains valid, the party accesses Jira connections and operations permitted by its assigned scopes.

### Impact Assessment

Successful exploitation may allow unauthorized use of the victim's Maton account and connected Jira resources. The precise impact depends on the API key's scopes and the Jira permissions associated with the managed OAuth c
...[truncated 405 chars]
Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a presence check that does not disclose the value:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Additional hardening measures:

  1. Explicitly warn users never to print, paste, log, or share API keys.
  2. Redact bearer tokens from agent transcripts, command logs, telemetry, and error output.
  3. Recommend rotating the key immediately if it has appeared in terminal output or a shared artifact.
  4. Grant the Maton key and connected Jira identity only the scopes required for the intended operation.
  5. Prefer a secret manager or protected environment injection mechanism over plaintext shell configuration.
  6. Keep network requests restricted to the documented HTTPS service and clearly disclose that Jira access is mediated by api.maton.ai.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is overly broad and encourages use for generic API integration, webhook configuration, and system-connection tasks well beyond a narrowly scoped Jira skill. In an agent environment, broad invocation criteria can cause the skill to be selected in unintended contexts, increasing the chance of unnecessary credential use, external requests, or destructive API actions against the wrong system.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section claims advanced software engineering and code-review capabilities unrelated to Jira issue/search/board management. Elsewhere the document consistently presents the skill as a Jira API/OAuth/JQL tool, so these lines actively conflict with the stated intent rather than merely omitting details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises create and update issue operations and broader management actions without documenting any confirmation, preview, or authorization checks for state-changing requests. In an agentic workflow, that omission makes accidental or prompt-induced destructive changes more likely, especially when combined with write and exec tool access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest and earlier capability sections describe JQL search, creating/updating issues, and managing boards, but do not mention delete/close operations. This creates an intent-level contradiction in the documentation about what the skill actually does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.