Back to skill

Security audit

Gmail

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill is mostly purpose-aligned, but it exposes high-privilege mailbox actions and unsafe credential-handling instructions without enough safeguards.

Review before installing. Use this only with a Maton account and Gmail scopes you are comfortable granting, avoid running troubleshooting that prints the API key, explicitly choose the Gmail connection when multiple accounts exist, and require confirmation before sending email, trashing messages, changing labels, deleting connections, or sending drafts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:308
Finding

Full Maton API Key Exposed in Terminal Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 308-310
Vulnerability Type: Secret exposure through terminal and log output
Risk Level: High

bash
echo $MATON_API_KEY

Technical Analysis

The troubleshooting instructions print the complete MATON_API_KEY to standard output. Terminal transcripts, shell-session recordings, CI logs, remote support tools, and agent execution histories may retain this output after troubleshooting is complete.

The key is used as a bearer credential for gateway.maton.ai and ctrl.maton.ai. Bearer credentials generally provide access based on possession, so an attacker who captures the printed value may use it without knowing any additional secret. The exposed privileges depend on the Maton account and its connected Gmail OAuth scopes.

Attack Path

  1. A user or automated agent encounters an authentication problem.
  2. The documented troubleshooting procedure is executed.
  3. The complete MATON_API_KEY is printed to the terminal.
  4. The value is retained in a transcript, log, screen capture, or support record.
  5. An attacker with access to that record extracts the key.
  6. The attacker submits the key as an Authorization: Bearer credential to Maton endpoints.
  7. Subject to the key's permissions and active connections, the attacker accesses or manipulates connected Gmail resources.

Impact Assessment

Successful exploitation may permit authentication to the Maton service under the victim's account. Depending on the OAuth scopes granted to connected Gmail accounts, the attacker could potentially list and read messages, inspect threads and labels, create or send drafts, send email, change message labels, or move messages to trash. The compromise may affect every connection accessible through the exposed key rather than only the connection involved in troubleshooting.

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to print the complete environment-variable value.
  • Test only whether the variable exists, for example:
    bash
    if [ -n "${MATON_API_KEY:-}" ]; then
      echo "MATON_API_KEY is set"
    else
      echo "MATON_API_KEY is not set"
    fi
    
  • If credential identification is necessary, display only a short masked suffix and never enough of the key to enable authentication.
  • Configure agent runners, CI systems, and support tooling to redact MATON_API_KEY values from command output.
  • Advise users to revoke and rotate any key that has already appeared in logs or transcripts.
  • Apply minimal Gmail OAuth scopes and separate credentials by environment or use case to reduce the impact of a leaked key.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

OAuth Connection Session Token Exposed in Command Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 81-111
Vulnerability Type: Sensitive OAuth session URL disclosed through terminal output
Risk Level: Medium

bash
python <<'EOF'
import urllib.request, os, json
data = json.dumps({'app': 'google-mail'}).encode()
req = urllib.request.Request('https://ctrl.maton.ai/connections', data=data, method='POST')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
req.add_header('Content-Type', 'application/json')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

The documented response includes a token-bearing URL:

json
{
  "connection": {
    "connection_id": "21fd90f9-5935-43cd-b6c8-bde9d915ca80",
    "status": "ACTIVE",
    "creation_time": "2025-12-08T07:20:53.488460Z",
    "last_updated_time": "2026-01-31T20:03:32.593153Z",
    "url": "https://connect.maton.ai/?session_token=...",
    "app": "google-mail",
    "metadata": {}
  }
}

Technical Analysis

The connection-creation example serializes and prints the entire server response. According to the documented response schema, that response contains a session_token in the query string of an OAuth connection URL.

Token-bearing URLs are sensitive because terminal transcripts and logs may preserve the full URL. URLs may also leak through copying, screenshots, browser history, monitoring systems, or support records. The practical exploitability depends on server-side properties that are not established by the project files, including token lifetime, single-use enforcement, session binding, and whether completing the OAuth flow requires additional user interaction.

Attack Path

  1. A user or agent creates a Google Mail connection using the documented command.
  2. The complete JSON response, including the token-bearing connection URL, is printed.
  3. A terminal logger, transcript collector, screen capture, or anothe ...[truncated 873 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not print the complete connection-creation response to shared terminal output.
  • Parse the response and handle the connection URL through a trusted local browser-opening mechanism without logging it.
  • If displaying the URL is unavoidable, clearly warn that it is sensitive and must not be copied into logs, tickets, or transcripts.
  • Redact the session_token from diagnostics and structured logs.
  • Ensure server-side session tokens are short-lived, cryptographically random, single-use, and bound to the initiating account and connection request.
  • Invalidate the token immediately after successful authorization or cancellation.
  • Prevent token-bearing query strings from entering HTTP referrer data, analytics, browser synchronization, and proxy logs where feasible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill guidance says to use this skill whenever users want to interact with Gmail, which is broad enough to capture many routine email requests without any built-in qualification for sensitivity or required confirmation. In the context of a capability that can read, send, trash, and manage mail via managed OAuth, overly broad routing increases the chance that an agent will invoke a high-privilege integration for ambiguous requests and expose or modify sensitive mailbox data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes operational examples for sending messages, modifying labels, trashing messages, creating drafts, and sending drafts, but does not pair those capabilities with explicit warnings or confirmation requirements. Because this is a Gmail skill with real account access through OAuth, an agent could perform irreversible or user-visible actions such as sending email or trashing messages based on ambiguous prompts, causing privacy, integrity, and social-engineering harm.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_resource_identifier

Example code exposes a concrete connection_id instead of a placeholder.

Critical
Code
suspicious.exposed_resource_identifier
Location
SKILL.md:103