T09 · Insecure Skill Coding Practices
- Location
SKILL.md:276- Finding
API Credential Exposed Through Troubleshooting Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 276-280
Vulnerability Type: API key disclosure through terminal output
Risk Level: HighVulnerable Code Snippet:
shell Troubleshooting Check API key echo $MATON_API_KEYTechnical Analysis
The troubleshooting procedure instructs users or agents to print the complete
MATON_API_KEYvalue to standard output. Terminal output may be retained in agent transcripts, continuous-integration logs, shell history recordings, debugging reports, or shared terminal sessions.The instruction does not mask the credential, validate only its presence, or warn users against publishing the resulting output. Because the API key authenticates requests to Maton's connection-management and Notion gateway services, disclosure can give another party access to the resources associated with the key.
Attack Path
- A user or agent encounters an authentication or connection problem.
- The troubleshooting instructions are followed and
echo $MATON_API_KEYis executed. - The complete credential appears in terminal output.
- The output is retained in an agent conversation, CI log, diagnostic report, screen recording, or shared terminal.
- An attacker with access to that output extracts the API key.
- The attacker submits the key in an
Authorization: Bearerheader to Maton's gateway or connection-management API. - The attacker accesses or modifies resources permitted by the victim's associated Notion OAuth connection.
Impact Assessment
Successful exploitation can expose the Maton account's connection metadata and grant access to connected Notion resources within the OAuth connection's effective permissions. Depending on those permissions, the attacker may be able to search workspace content, read pages and databases, enumerate users, create or modify content, archive pages, delete blocks, or delete managed connections.
- Remediation
View remediation
Remediation Suggestions
-
Remove the instruction that prints the complete API key.
-
Test only whether the environment variable is present:
shell if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is configured" else echo "MATON_API_KEY is not configured" fi -
If identification is necessary, display only a short, non-sensitive fingerprint rather than the key itself.
-
Add explicit guidance prohibiting credentials from being included in logs, screenshots, support tickets, or agent transcripts.
-
Configure CI and agent environments to redact
MATON_API_KEYfrom command output. -
Rotate any API key that has already been printed into persistent or shared output.
-
Apply least-privilege permissions to the OAuth connection associated with each key.
-
