T09 · Insecure Skill Coding Practices
- Location
SKILL.md:308- Finding
Full Maton API Key Exposed in Terminal Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 308-310
Vulnerability Type: Secret exposure through terminal and log output
Risk Level: Highbash echo $MATON_API_KEYTechnical Analysis
The troubleshooting instructions print the complete
MATON_API_KEYto standard output. Terminal transcripts, shell-session recordings, CI logs, remote support tools, and agent execution histories may retain this output after troubleshooting is complete.The key is used as a bearer credential for
gateway.maton.aiandctrl.maton.ai. Bearer credentials generally provide access based on possession, so an attacker who captures the printed value may use it without knowing any additional secret. The exposed privileges depend on the Maton account and its connected Gmail OAuth scopes.Attack Path
- A user or automated agent encounters an authentication problem.
- The documented troubleshooting procedure is executed.
- The complete
MATON_API_KEYis printed to the terminal. - The value is retained in a transcript, log, screen capture, or support record.
- An attacker with access to that record extracts the key.
- The attacker submits the key as an
Authorization: Bearercredential to Maton endpoints. - Subject to the key's permissions and active connections, the attacker accesses or manipulates connected Gmail resources.
Impact Assessment
Successful exploitation may permit authentication to the Maton service under the victim's account. Depending on the OAuth scopes granted to connected Gmail accounts, the attacker could potentially list and read messages, inspect threads and labels, create or send drafts, send email, change message labels, or move messages to trash. The compromise may affect every connection accessible through the exposed key rather than only the connection involved in troubleshooting.
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to print the complete environment-variable value.
- Test only whether the variable exists, for example:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fi - If credential identification is necessary, display only a short masked suffix and never enough of the key to enable authentication.
- Configure agent runners, CI systems, and support tooling to redact
MATON_API_KEYvalues from command output. - Advise users to revoke and rotate any key that has already appeared in logs or transcripts.
- Apply minimal Gmail OAuth scopes and separate credentials by environment or use case to reduce the impact of a leaked key.
