T09 · Insecure Skill Coding Practices
- Location
SKILL.md:150- Finding
API Credential Disclosure Through Shell Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 150–153
Vulnerability Type: Sensitive credential exposure
Risk Level: HighVulnerable Code
markdown 1. Check that the `MATON_API_KEY` environment variable is set: ```bash echo $MATON_API_KEYtext ### Technical Analysis The troubleshooting instructions reveal the complete value of `MATON_API_KEY` by printing it to standard output. Verifying whether an environment variable is configured does not require disclosing its content. When an AI Agent or user executes this command, the credential may be retained in Agent conversation transcripts, terminal history or recordings, CI/CD logs, debugging output, shared screens, or centralized logging systems. Although the API key is not hardcoded in the project, instructing users to expose it creates a plaintext-secret disclosure vulnerability. The Skill also uses this credential as a Bearer token for requests to `https://api.maton.ai/pipedrive/api/v1/deals` at lines 69–70. Consequently, anyone who obtains the disclosed value may attempt to authenticate to the Maton API and access the Pipedrive integration associated with the victim. ### Attack Path 1. A user experiences an authentication or configuration problem. 2. The user or Agent follows the Skill's troubleshooting procedure. 3. `echo $MATON_API_KEY` prints the complete secret to standard output. 4. The output is stored in an Agent transcript, CI log, terminal recording, debugging record, or another observable location. 5. An attacker or unauthorized collaborator obtains the exposed credential. 6. The attacker supplies the credential as a Bearer token to the Maton API. 7. Subject to the token's actual permissions, the attacker may query or modify connected Pipedrive resources. ### Impact Assessment Successful exploitation exposes the authority assigned to the affected API key. Based on the Skill's declared functionality, that authority ...[truncated 473 chars]- Remediation
View remediation
Remediation Suggestions
Replace the secret-printing command with a presence check that never outputs the credential:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiApply the following additional controls:
- Explicitly prohibit printing, logging, or including the key in Agent prompts and transcripts.
- Redact authorization headers and environment-variable values from diagnostic output.
- Use narrowly scoped, revocable credentials and rotate any key that may already have appeared in logs.
- Configure CI/CD and Agent platforms to mask
MATON_API_KEY. - Document that the credential and CRM requests are sent to the third-party
api.maton.aiservice. - Prefer a secret manager or protected credential store over general shell environment handling when the runtime supports it.
- Review logs and transcripts for prior exposure and delete or restrict affected records where feasible.
