maple-onboard

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to hardcode API ingest keys directly into the source code bootstrap files. It mandates that no environment variables or .env files should be used, claiming the keys are 'write-only', which leads to credential exposure in version control systems.
  • Evidence: 'The ingest API key is project-scoped + write-only... inline it directly in the OTel bootstrap source... No .env files, no deploy-target wiring.'
  • [DATA_EXFILTRATION]: The skill instructs the agent to automatically collect and transmit sensitive repository metadata as resource attributes to the vendor endpoint.
  • Evidence: 'Set resource attributes on the OTel resource for every service: service.name, service.version, deployment.environment.name, and vcs.repository.url.full — the canonical https URL of the repo.'
  • [COMMAND_EXECUTION]: The skill provides instructions to execute a command that modifies the agent's own execution environment by adding a remote MCP server.
  • Evidence: 'claude mcp add --transport http maple https://api.maple.dev/mcp'
  • [PERSISTENCE]: By adding an MCP server to the user's agent configuration, the skill establishes a persistent extension that can provide tools and execute code in future sessions.
  • Evidence: 'This edits the user's Claude Code config. ... Suggest installing the Maple MCP server so the agent ... can query telemetry directly next time.'
  • [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface as it scans every application and service in a repository and interpolates project metadata into the generated instrumentation code without sanitization.
  • Ingestion points: Workspace manifests (pnpm-workspace.yaml, package.json, go.work, Cargo.toml, pyproject.toml) and environment variables (VERCEL_GIT_REPO_SLUG, etc.).
  • Boundary markers: Absent; the skill does not specify delimiters for interpolated metadata.
  • Capability inventory: File writing (bootstrap code), package installation (npm install, pip install), and configuration modification (claude mcp add).
  • Sanitization: Absent; the skill instructs to read these values and 'hardcode' them into the SDK initialization.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — maple-onboard