T09 · Insecure Skill Coding Practices
- Location
SKILL.md:262- Finding
API Key Exposure Through Troubleshooting Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:262-265
Vulnerability Type: Sensitive credential exposure through terminal output
Risk Level: MediumVulnerable Code:
markdown 1. Check that the `MATON_API_KEY` environment variable is set: ```bash echo $MATON_API_KEYtext ### Technical Analysis The troubleshooting instructions print the complete `MATON_API_KEY` value to standard output. Verifying whether an environment variable exists does not require disclosing its contents. Terminal output can be retained in AI-agent tool logs, CI/CD logs, shell transcripts, screen recordings, support records, or shared terminal sessions. Because the key authenticates requests to the Maton service, exposing it may permit unauthorized use of the Slack connections and permissions associated with that Maton account. ### Attack Path 1. A user encounters an authentication problem and follows the documented troubleshooting procedure. 2. The user executes `echo $MATON_API_KEY`. 3. The complete API key appears in terminal output. 4. The output is captured by an agent log, CI system, recording, shared session, or another party with terminal visibility. 5. An attacker retrieves the exposed key. 6. The attacker supplies it as a bearer credential to `https://api.maton.ai`. 7. Subject to the key's configured permissions and connected OAuth account, the attacker accesses Maton connection information or invokes proxied Slack API operations. ### Impact Assessment Successful exploitation exposes the Maton bearer credential. The resulting privileges are limited to those assigned to the compromised key and its connected Slack OAuth account, but may include reading messages, channels, users, files, and reactions. Depending on granted Slack scopes and application controls, it may also enable message or channel modifications. The project requires explicit user approval for legitimate write operations, but an attacker u ...[truncated 120 chars]- Remediation
View remediation
Remediation Suggestions
Replace the secret-printing command with a non-disclosing presence check:
bash if [ -n "${MATON_API_KEY:-}" ]; then echo "MATON_API_KEY is set" else echo "MATON_API_KEY is not set" fiAdditional hardening measures:
- Explicitly warn users never to print, log, paste, or commit the API key.
- Redact bearer tokens from agent, shell, HTTP-debugging, and CI/CD logs.
- Store the key in an approved secret manager rather than plaintext configuration.
- Use narrowly scoped credentials and separate keys for development and production.
- Support prompt key revocation and rotation through Maton.
- If the documented command has already been used in a logged environment, remove the retained output and rotate the affected key.
