Back to skill

Security audit

Pipedrive API工具

Security checks for vulnerabilities and agentic risk

Overview

This Pipedrive skill appears intended for CRM API work, but it asks for broad local execution/file authority and includes unsafe credential-handling guidance.

Review before installing. Use only with a narrowly scoped, revocable MATON_API_KEY, avoid printing or pasting the key into agent chats or logs, and do not grant broad read/write/exec authority unless you explicitly need it for a specific Pipedrive task. Treat CRM records as sensitive business and personal data when sending requests through api.maton.ai.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:150
Finding

API Credential Disclosure Through Shell Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 150–153
Vulnerability Type: Sensitive credential exposure
Risk Level: High

Vulnerable Code

markdown
1. Check that the `MATON_API_KEY` environment variable is set:

```bash
echo $MATON_API_KEY
text

### Technical Analysis

The troubleshooting instructions reveal the complete value of `MATON_API_KEY` by printing it to standard output. Verifying whether an environment variable is configured does not require disclosing its content.

When an AI Agent or user executes this command, the credential may be retained in Agent conversation transcripts, terminal history or recordings, CI/CD logs, debugging output, shared screens, or centralized logging systems. Although the API key is not hardcoded in the project, instructing users to expose it creates a plaintext-secret disclosure vulnerability.

The Skill also uses this credential as a Bearer token for requests to `https://api.maton.ai/pipedrive/api/v1/deals` at lines 69–70. Consequently, anyone who obtains the disclosed value may attempt to authenticate to the Maton API and access the Pipedrive integration associated with the victim.

### Attack Path

1. A user experiences an authentication or configuration problem.
2. The user or Agent follows the Skill's troubleshooting procedure.
3. `echo $MATON_API_KEY` prints the complete secret to standard output.
4. The output is stored in an Agent transcript, CI log, terminal recording, debugging record, or another observable location.
5. An attacker or unauthorized collaborator obtains the exposed credential.
6. The attacker supplies the credential as a Bearer token to the Maton API.
7. Subject to the token's actual permissions, the attacker may query or modify connected Pipedrive resources.

### Impact Assessment

Successful exploitation exposes the authority assigned to the affected API key. Based on the Skill's declared functionality, that authority
...[truncated 473 chars]
Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a presence check that never outputs the credential:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Apply the following additional controls:

  1. Explicitly prohibit printing, logging, or including the key in Agent prompts and transcripts.
  2. Redact authorization headers and environment-variable values from diagnostic output.
  3. Use narrowly scoped, revocable credentials and rotate any key that may already have appeared in logs.
  4. Configure CI/CD and Agent platforms to mask MATON_API_KEY.
  5. Document that the credential and CRM requests are sent to the third-party api.maton.ai service.
  6. Prefer a secret manager or protected credential store over general shell environment handling when the runtime supports it.
  7. Review logs and transcripts for prior exposure and delete or restrict affected records where feasible.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Claiming system command-execution capability for a Pipedrive integration is dangerous because it expands the skill from remote API access into arbitrary local code or shell action. In agent environments, this can lead to filesystem access, secret exposure, persistence, or lateral movement if the skill is selected under the pretense of simple CRM automation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is overly broad, covering generic efficiency, automation, batch processing, and workflow optimization scenarios. That makes accidental invocation more likely in unrelated contexts, which is especially risky here because the skill also claims unnecessary local capabilities and authenticated external transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description explicitly states '支持中文交互,无需复杂配置即开即用,' indicating Chinese interaction support as a default behavior, while the display name is also Chinese. The document does not clearly offer the user a language choice or state that Chinese is optional, which can violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example performs an authenticated external request using an environment-sourced bearer token, but the documentation does not prominently warn users that credentials and potentially sensitive CRM data will be transmitted to a third-party service endpoint. In an agent setting, such examples can normalize silent credential use and remote data transfer without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example explicitly sends an authenticated request to an external service endpoint using a bearer token. External transmission is expected for an API integration, but it is still security-relevant because the skill handles potentially sensitive CRM data and the documentation does not sufficiently disclose transmission scope, destination trust boundaries, or data minimization expectations.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/pipedrive/api/v1/deals')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 170)May include surrounding context.

md
### Troubleshooting: Invalid App Name
1. Ensure your URL path starts with `pipedrive`. For example:

* Correct: `https://api.maton.ai/pipedrive/api/v1/deals`
* Incorrect: `https://api.maton.ai/api/v1/deals`
> **处理方式**: 参考上表中的错误场景说明,按照对应建议进行处理和恢复.
## 前置条件

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
### Troubleshooting: Invalid App Name
1. Ensure your URL path starts with `pipedrive`. For example:

* Correct: `https://api.maton.ai/pipedrive/api/v1/deals`
* Incorrect: `https://api.maton.ai/api/v1/deals`
> **处理方式**: 参考上表中的错误场景说明,按照对应建议进行处理和恢复.
## 前置条件

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a Pipedrive API integration, but later advertises unrelated capabilities such as generic file processing and command execution. This scope mismatch increases the chance that an agent will invoke powerful local actions that users would not reasonably expect from a CRM API skill, enabling overbroad access and risky behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad file read/parse/write capability is not justified by the stated Pipedrive API function and materially increases the local attack surface. In context, a user expecting CRM operations could unknowingly authorize access to local files, including sensitive documents or configuration data unrelated to Pipedrive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.