Back to skill

Security audit

Google Drive

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Google Drive cURL guide, but it includes high-impact file and sharing commands plus unsafe guidance to print an API key.

Review this carefully before installing or using it. Use a narrowly scoped Maton API key and Google Drive connection, avoid running delete/share/upload commands unless you have confirmed the exact target IDs, and do not run the documented echo command for the API key; check only whether the variable is set.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
Skill.md:178
Finding

API Key Exposure Through Terminal Output

Content
View full analysis

Vulnerability Details

File Location: Skill.md, line 178
Vulnerability Type: Sensitive credential exposure through insecure troubleshooting guidance
Risk Level: Medium

Vulnerable Code:

bash
echo $MATON_API_KEY

Technical Analysis

The troubleshooting instructions recommend printing the complete MATON_API_KEY environment variable to standard output. Because this value is used as a bearer token in the documented Authorization header, possession of the token may be sufficient to authenticate requests without additional proof of identity.

Terminal output can be exposed through shell transcripts, CI/CD logs, AI-agent execution logs, screen recordings, shared support artifacts, or observation by another user. The command should verify whether the variable is configured without revealing its value.

Attack Path

  1. A user follows the troubleshooting instructions and executes echo $MATON_API_KEY.
  2. The complete bearer token is printed to the terminal.
  3. The output is captured in a log, transcript, screenshot, recording, or other accessible artifact.
  4. An attacker obtains the exposed token.
  5. The attacker places the token in an Authorization: Bearer header and sends requests to the documented Maton endpoints.
  6. Until the token is revoked or expires, the attacker can attempt operations authorized for the associated Maton account and Google Drive connection.

Impact Assessment

A disclosed API key may permit unauthorized use of the Maton gateway and control APIs within the permissions granted to the token and its associated connections. Potentially exposed operations documented by this Skill include:

  • Listing and searching Google Drive files
  • Reading metadata and downloading or exporting content
  • Creating, uploading, copying, moving, and modifying files
  • Sharing files with other users
  • Deleting files
  • Viewing, creating, or deleting Google Drive connections

The actual impact is constrained by server-side auth ...[truncated 123 chars]

Remediation
View remediation

Remediation Suggestions

Remove the command that prints the credential. Check only whether the environment variable is populated:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Additional hardening measures:

  1. Revoke and rotate any API key that may already have appeared in logs, transcripts, screenshots, or support records.
  2. Redact bearer tokens from application, proxy, CI/CD, and AI-agent logs.
  3. Avoid enabling shell tracing such as set -x while handling credentials.
  4. Store the key in an approved secret manager and inject it only when required.
  5. Use short-lived and narrowly scoped credentials where the platform supports them.
  6. Apply least-privilege permissions to the associated Google Drive connection.
  7. Add automated secret scanning and output-redaction controls to documentation validation and execution environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · Skill.md (reported line 1)May include surrounding context.

md
# Google Drive (Maton Gateway) – cURL Guide

Access the Google Drive API with managed OAuth authentication using cURL.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents destructive and state-changing Google Drive operations such as create, update, move, delete, copy, upload, and permission changes, but it does not warn users about the risk of data loss, unintended modification, or accidental sharing. In an agent-skill context, exposing these operations as ready-to-run examples can facilitate unsafe automation or user mistakes, especially because delete and sharing actions are presented alongside read-only actions without extra safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.