T09 · Insecure Skill Coding Practices
- Location
SKILL.md:597- Finding
API Key Exposure Through Troubleshooting Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 597
Vulnerability Type: Credential exposure through insecure diagnostic guidance
Risk Level: MediumVulnerable Code:
bash echo $MATON_API_KEYTechnical Analysis
The troubleshooting instructions print the complete
MATON_API_KEYto standard output. This secret may consequently be retained in CI/CD logs, agent tool transcripts, terminal recordings, support bundles, or other monitoring systems.The key authenticates requests to Maton's gateway and control services. Although it does not independently grant new third-party authorization, possession of it may allow an attacker to exercise OAuth connections that the user has already authorized. The exposure therefore violates secret-handling best practices and can convert access to otherwise low-sensitivity logs into access to connected third-party services.
Attack Path
- A user or automated agent follows the documented troubleshooting procedure.
- The shell expands
MATON_API_KEYand writes the complete credential to standard output. - The output is captured in a terminal transcript, agent conversation, CI log, screen recording, or support artifact.
- An attacker with access to that output obtains the credential.
- The attacker submits the key in an
Authorization: Bearerheader to Maton's gateway or connection-management endpoints. - Subject to the user's existing OAuth connections and their scopes, the attacker reads data or invokes mutation and deletion operations exposed by those connections.
Impact Assessment
Successful exploitation may provide access to the victim's active Maton account connections. The exact impact depends on the third-party services connected and the OAuth scopes previously granted. Potential consequences include:
- Reading business, customer, communication, financial, or workspace data.
- Creating or modifying records and messages.
- Invokin ...[truncated 408 chars]
- Remediation
View remediation
Remediation Suggestions
Replace the secret-printing command with a presence-only check that never reveals the value:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiApply the following additional hardening measures:
- Explicitly warn users never to print, log, paste, or commit the API key.
- Redact
Authorizationheaders and known secret values from agent output, application logs, CI logs, and support bundles. - Avoid enabling shell tracing such as
set -xwhile commands use the credential. - Store the key in an approved secret manager and inject it only into the processes that require it.
- Rotate the key immediately if it has appeared in any log or transcript.
- Where supported, use short-lived, scoped credentials and restrict gateway access by service, operation, environment, or network origin.
- Monitor gateway and connection-management activity for anomalous use following suspected disclosure.
