Back to skill

Security audit

Api Gateway.Disabled

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broad API gateway that can modify, delete, send, and administer data across many connected services, with limited safety guidance and a documented command that can reveal the API key.

Install only if you are comfortable letting the agent use Maton to act on your authorized third-party connections. Use least-privilege OAuth scopes, specify the intended connection when multiple exist, require explicit human confirmation before deletes, sends, financial/admin changes, or public posts, and do not print or paste the Maton API key; rotate it if it has appeared in logs or transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:597
Finding

API Key Exposure Through Troubleshooting Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 597
Vulnerability Type: Credential exposure through insecure diagnostic guidance
Risk Level: Medium

Vulnerable Code:

bash
echo $MATON_API_KEY

Technical Analysis

The troubleshooting instructions print the complete MATON_API_KEY to standard output. This secret may consequently be retained in CI/CD logs, agent tool transcripts, terminal recordings, support bundles, or other monitoring systems.

The key authenticates requests to Maton's gateway and control services. Although it does not independently grant new third-party authorization, possession of it may allow an attacker to exercise OAuth connections that the user has already authorized. The exposure therefore violates secret-handling best practices and can convert access to otherwise low-sensitivity logs into access to connected third-party services.

Attack Path

  1. A user or automated agent follows the documented troubleshooting procedure.
  2. The shell expands MATON_API_KEY and writes the complete credential to standard output.
  3. The output is captured in a terminal transcript, agent conversation, CI log, screen recording, or support artifact.
  4. An attacker with access to that output obtains the credential.
  5. The attacker submits the key in an Authorization: Bearer header to Maton's gateway or connection-management endpoints.
  6. Subject to the user's existing OAuth connections and their scopes, the attacker reads data or invokes mutation and deletion operations exposed by those connections.

Impact Assessment

Successful exploitation may provide access to the victim's active Maton account connections. The exact impact depends on the third-party services connected and the OAuth scopes previously granted. Potential consequences include:

  • Reading business, customer, communication, financial, or workspace data.
  • Creating or modifying records and messages.
  • Invokin ...[truncated 408 chars]
Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a presence-only check that never reveals the value:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Apply the following additional hardening measures:

  1. Explicitly warn users never to print, log, paste, or commit the API key.
  2. Redact Authorization headers and known secret values from agent output, application logs, CI logs, and support bundles.
  3. Avoid enabling shell tracing such as set -x while commands use the credential.
  4. Store the key in an approved secret manager and inject it only into the processes that require it.
  5. Rotate the key immediately if it has appeared in any log or transcript.
  6. Where supported, use short-lived, scoped credentials and restrict gateway access by service, operation, environment, or network origin.
  7. Monitor gateway and connection-management activity for anomalous use following suspected disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (526)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 47)May include surrounding context.

Delete Contact

bash
DELETE /active-campaign/api/3/contacts/{contactId}

Tags

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/active-campaign/README.md (reported line 87)May include surrounding context.

Remove Tag from Contact

bash
DELETE /active-campaign/api/3/contactTags/{contactTagId}

Lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/acuity-scheduling/README.md (reported line 127)May include surrounding context.

Delete Block

bash
DELETE /acuity-scheduling/api/v1/blocks/{id}

List Forms

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/airtable/README.md (reported line 99)May include surrounding context.

Delete Records

bash
DELETE /airtable/v0/{baseId}/{tableIdOrName}?records[]=recXXXXX&records[]=recYYYYY

List Bases

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 64)May include surrounding context.

Delete a Task

bash
DELETE /asana/api/1.0/tasks/{task_gid}

Get Subtasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/asana/README.md (reported line 134)May include surrounding context.

Delete Webhook

bash
DELETE /asana/api/1.0/webhooks/{webhook_gid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 76)May include surrounding context.

Delete Record

bash
DELETE /attio/v2/objects/{object}/records/{record_id}

List Tasks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 144)May include surrounding context.

Delete Note

bash
DELETE /attio/v2/notes/{note_id}

Comments

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/attio/README.md (reported line 248)May include surrounding context.

Delete List Entry

bash
DELETE /attio/v2/lists/{list}/entries/{entry_id}

Meetings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
81% confidence
Finding

The documented DELETE route is a destructive action that can be abused by an agent or caller if user-controlled parameters such as table_id and row_id are passed through without strong authorization checks and confirmation. In an API-gateway skill that fronts many external services, exposing raw destructive endpoints increases the chance of unintended or unauthorized data deletion, especially when combined with the auth-model ambiguity noted above.

Content

Scanner excerpt · references/baserow/README.md (reported line 57)May include surrounding context.

Delete Row

bash
DELETE /baserow/api/database/rows/table/{table_id}/{row_id}/

Batch Create Rows

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/beehiiv/README.md (reported line 61)May include surrounding context.

Delete Subscription

bash
DELETE /beehiiv/v2/publications/{publication_id}/subscriptions/{subscription_id}

Posts

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 72)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 73)May include surrounding context.

Delete Folder

bash
DELETE /box/2.0/folders/{folder_id}
DELETE /box/2.0/folders/{folder_id}?recursive=true

Get File

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 98)May include surrounding context.

Delete File

bash
DELETE /box/2.0/files/{file_id}

Create Shared Link

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 141)May include surrounding context.

Trash

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 142)May include surrounding context.

bash
GET /box/2.0/folders/trash/items
DELETE /box/2.0/files/{file_id}/trash
DELETE /box/2.0/folders/{folder_id}/trash

Collections

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/box/README.md (reported line 160)May include surrounding context.

bash
GET /box/2.0/webhooks
POST /box/2.0/webhooks
DELETE /box/2.0/webhooks/{webhook_id}

Pagination

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The documented DELETE endpoint accepts a path parameter identifier and performs a destructive action on live contact data. While the README itself is benign reference material, exposing parameterized destructive operations without guardrails in an agent skill increases the chance of tool misuse, including deletion of the wrong contact through prompt or parameter manipulation.

Content

Scanner excerpt · references/brevo/README.md (reported line 56)May include surrounding context.

Delete Contact

bash
DELETE /brevo/v3/contacts/{identifier}

Lists

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The campaign send operation is especially risky because it can immediately broadcast to mailing lists at scale, yet the README does not warn about irreversible mass delivery. In an agent-driven integration, this materially raises the risk of accidental bulk sends, compliance exposure, and brand damage.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 50)May include surrounding context.

Delete Event Type

bash
DELETE /cal-com/v2/event-types/{eventTypeId}

Event Type Webhooks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 77)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/event-types/{eventTypeId}/webhooks/{webhookId}

Bookings

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 130)May include surrounding context.

Delete Schedule

bash
DELETE /cal-com/v2/schedules/{scheduleId}

Availability Slots

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cal-com/README.md (reported line 188)May include surrounding context.

Delete Webhook

bash
DELETE /cal-com/v2/webhooks/{webhookId}

Teams

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/calendly/README.md (reported line 89)May include surrounding context.

Delete Webhook Subscription

bash
DELETE /calendly/webhook_subscriptions/{uuid}

Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/callrail/README.md (reported line 120)May include surrounding context.

Delete Tag

bash
DELETE /callrail/v3/a/{account_id}/tags/{tag_id}.json

Users

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete Google Sheets spreadsheet ID instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:495

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:94