Back to skill

Security audit

Slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill is mostly purpose-aligned, but it under-declares its write and network authority and includes unsafe API-key troubleshooting guidance.

Review this before installing if your Slack workspace contains sensitive data. Use least-privilege Maton and Slack scopes, require confirmation before any send/create/update/delete action, avoid printing MATON_API_KEY, and be comfortable with routing Slack API traffic through Maton rather than directly to Slack.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:262
Finding

API Key Exposure Through Troubleshooting Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:262-265
Vulnerability Type: Sensitive credential exposure through terminal output
Risk Level: Medium

Vulnerable Code:

markdown
1. Check that the `MATON_API_KEY` environment variable is set:

```bash
echo $MATON_API_KEY
text

### Technical Analysis

The troubleshooting instructions print the complete `MATON_API_KEY` value to standard output. Verifying whether an environment variable exists does not require disclosing its contents.

Terminal output can be retained in AI-agent tool logs, CI/CD logs, shell transcripts, screen recordings, support records, or shared terminal sessions. Because the key authenticates requests to the Maton service, exposing it may permit unauthorized use of the Slack connections and permissions associated with that Maton account.

### Attack Path

1. A user encounters an authentication problem and follows the documented troubleshooting procedure.
2. The user executes `echo $MATON_API_KEY`.
3. The complete API key appears in terminal output.
4. The output is captured by an agent log, CI system, recording, shared session, or another party with terminal visibility.
5. An attacker retrieves the exposed key.
6. The attacker supplies it as a bearer credential to `https://api.maton.ai`.
7. Subject to the key's configured permissions and connected OAuth account, the attacker accesses Maton connection information or invokes proxied Slack API operations.

### Impact Assessment

Successful exploitation exposes the Maton bearer credential. The resulting privileges are limited to those assigned to the compromised key and its connected Slack OAuth account, but may include reading messages, channels, users, files, and reactions. Depending on granted Slack scopes and application controls, it may also enable message or channel modifications.

The project requires explicit user approval for legitimate write operations, but an attacker u
...[truncated 120 chars]
Remediation
View remediation

Remediation Suggestions

Replace the secret-printing command with a non-disclosing presence check:

bash
if [ -n "${MATON_API_KEY:-}" ]; then
  echo "MATON_API_KEY is set"
else
  echo "MATON_API_KEY is not set"
fi

Additional hardening measures:

  • Explicitly warn users never to print, log, paste, or commit the API key.
  • Redact bearer tokens from agent, shell, HTTP-debugging, and CI/CD logs.
  • Store the key in an approved secret manager rather than plaintext configuration.
  • Use narrowly scoped credentials and separate keys for development and production.
  • Support prompt key revocation and rotation through Maton.
  • If the documented command has already been used in a logged environment, remove the retained output and rotate the affected key.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises only a read tool, while the body documents message sending, channel management, deletion, and other write-capable actions. This capability mismatch can bypass operator expectations and policy gating, leading an agent or user to treat the skill as read-only when it can drive state-changing operations against Slack.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are generic terms such as oauth, api, managed, integration, and slack, which are broad enough to cause accidental activation in unrelated conversations. Over-broad activation increases the chance that an agent invokes this skill in the wrong context, exposing Slack-connected data or initiating external actions unnecessarily.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The declared base URL establishes that all requests are sent to api.maton.ai rather than directly to Slack, meaning the integration depends on a proxy that receives request metadata and potentially content. This is not inherently malicious, but it is a meaningful external transmission and trust-boundary expansion that users must understand.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Base URL

text
https://api.maton.ai/slack/{method}

Maton proxies requests to slack.com and automatically injects your OAuth token.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This finding duplicates the JavaScript example's external transmission pattern and represents the same underlying risk: authenticated outbound traffic to a proxy service. In an agent-execution setting, even documentation examples can normalize sending sensitive content externally without adequate confirmation controls.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

JavaScript

javascript
const response = await fetch('https://api.maton.ai/slack/api/chat.postMessage', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This finding duplicates the JavaScript example's external transmission pattern and represents the same underlying risk: authenticated outbound traffic to a proxy service. In an agent-execution setting, even documentation examples can normalize sending sensitive content externally without adequate confirmation controls.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

JavaScript

javascript
const response = await fetch('https://api.maton.ai/slack/api/chat.postMessage', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The code sample transmits message content and authorization data to api.maton.ai, which then relays to Slack. In context this is intended functionality, but it is still security-relevant because an agent following the sample would cause outbound data transfer and use privileged credentials against an external service.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
import os
import requests

response = requests.post(
    'https://api.maton.ai/slack/api/chat.postMessage',
    headers={'Authorization': f'Bearer {os.environ["MATON_API_KEY"]}'},
    json={'channel': 'C0123456', 'text': 'Hello!'}

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The code sample transmits message content and authorization data to api.maton.ai, which then relays to Slack. In context this is intended functionality, but it is still security-relevant because an agent following the sample would cause outbound data transfer and use privileged credentials against an external service.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
import os
import requests

response = requests.post(
    'https://api.maton.ai/slack/api/chat.postMessage',
    headers={'Authorization': f'Bearer {os.environ["MATON_API_KEY"]}'},
    json={'channel': 'C0123456', 'text': 'Hello!'}

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The Python sample performs an external POST to the Maton Slack proxy immediately after reading MATON_API_KEY from the environment. This creates a clear credential-use and data-egress path that is acceptable only when the user explicitly intends to interact with Slack through that service.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
import requests

response = requests.post(
    'https://api.maton.ai/slack/api/chat.postMessage',
    headers={'Authorization': f'Bearer {os.environ["MATON_API_KEY"]}'},
    json={'channel': 'C0123456', 'text': 'Hello!'}
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The troubleshooting snippet sends the bearer token to the connections endpoint to enumerate account connections. Even though it is framed as diagnostics, it still discloses credential use against an external service and can reveal account metadata if run in the wrong context.

Content

Scanner excerpt · SKILL.md (reported line 273)May include surrounding context.

bash
python <<'EOF'
import urllib.request, os, json
req = urllib.request.Request('https://api.maton.ai/connections')
req.add_header('Authorization', f'Bearer {os.environ["MATON_API_KEY"]}')
print(json.dumps(json.load(urllib.request.urlopen(req)), indent=2))
EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
### Troubleshooting: Invalid App Name
1. Ensure your URL path starts with `slack`. For example:

* Correct: `https://api.maton.ai/slack/api/chat.postMessage`
* Incorrect: `https://api.maton.ai/api/chat.postMessage`

## Resources

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
### Troubleshooting: Invalid App Name
1. Ensure your URL path starts with `slack`. For example:

* Correct: `https://api.maton.ai/slack/api/chat.postMessage`
* Incorrect: `https://api.maton.ai/api/chat.postMessage`

## Resources

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that no extra API key is needed, but the examples and operational flow clearly require MATON_API_KEY. This mismatch can mislead users and agents about the authentication model, causing unsafe assumptions about when credentials are required and potentially prompting insecure troubleshooting or failed auth handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The repeated trigger list remains vague and lacks boundaries on when the skill should activate. Repeating broad triggers reinforces accidental invocation risk and makes it harder for a host agent to distinguish benign mentions of APIs or OAuth from actual Slack-operation requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The summary and description present content in both Chinese and English, but the file does not state whether language should match user preference or provide an opt-in choice. This can conflict with language/locale policy expectations where the skill should not impose a language format without user selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.