api-gateway
Warn
Audited by Snyk on May 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to proxy requests through gateway.maton.ai (and ctrl.maton.ai) to fetch and read responses from many public third‑party services (e.g., GitHub, WordPress.com, Slack, Google Docs, YouTube) so the agent will ingest untrusted/user‑generated content as part of its workflow which could influence subsequent API calls or actions.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is an API gateway that explicitly lists and proxies specific financial and payments services (e.g., Stripe, Square, QuickBooks, Xero, WooCommerce) and ad platforms (e.g., Google Ads, Snapchat) and provides examples showing native Stripe calls. Because it exposes native API endpoints for payment gateways and ad/account APIs (which can include payment/transaction endpoints and budget updates), it grants the ability to perform direct financial actions via those provider APIs. This meets the "Direct Financial Execution" criteria.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata