T09 · Insecure Skill Coding Practices
- Location
Skill.md:178- Finding
API Key Exposure Through Terminal Output
- Content
View full analysis
Vulnerability Details
File Location:
Skill.md, line 178
Vulnerability Type: Sensitive credential exposure through insecure troubleshooting guidance
Risk Level: MediumVulnerable Code:
bash echo $MATON_API_KEYTechnical Analysis
The troubleshooting instructions recommend printing the complete
MATON_API_KEYenvironment variable to standard output. Because this value is used as a bearer token in the documentedAuthorizationheader, possession of the token may be sufficient to authenticate requests without additional proof of identity.Terminal output can be exposed through shell transcripts, CI/CD logs, AI-agent execution logs, screen recordings, shared support artifacts, or observation by another user. The command should verify whether the variable is configured without revealing its value.
Attack Path
- A user follows the troubleshooting instructions and executes
echo $MATON_API_KEY. - The complete bearer token is printed to the terminal.
- The output is captured in a log, transcript, screenshot, recording, or other accessible artifact.
- An attacker obtains the exposed token.
- The attacker places the token in an
Authorization: Bearerheader and sends requests to the documented Maton endpoints. - Until the token is revoked or expires, the attacker can attempt operations authorized for the associated Maton account and Google Drive connection.
Impact Assessment
A disclosed API key may permit unauthorized use of the Maton gateway and control APIs within the permissions granted to the token and its associated connections. Potentially exposed operations documented by this Skill include:
- Listing and searching Google Drive files
- Reading metadata and downloading or exporting content
- Creating, uploading, copying, moving, and modifying files
- Sharing files with other users
- Deleting files
- Viewing, creating, or deleting Google Drive connections
The actual impact is constrained by server-side auth ...[truncated 123 chars]
- A user follows the troubleshooting instructions and executes
- Remediation
View remediation
Remediation Suggestions
Remove the command that prints the credential. Check only whether the environment variable is populated:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiAdditional hardening measures:
- Revoke and rotate any API key that may already have appeared in logs, transcripts, screenshots, or support records.
- Redact bearer tokens from application, proxy, CI/CD, and AI-agent logs.
- Avoid enabling shell tracing such as
set -xwhile handling credentials. - Store the key in an approved secret manager and inject it only when required.
- Use short-lived and narrowly scoped credentials where the platform supports them.
- Apply least-privilege permissions to the associated Google Drive connection.
- Add automated secret scanning and output-redaction controls to documentation validation and execution environments.
