api-gateway

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
providers/cursor/plugin/skills/api-gateway/SKILL.md

SUSPICIOUS. The core gateway behavior and official install sources are coherent with the stated purpose, and the skill contains unusually strong safety guidance against secret extraction and unsafe automation. However, the purpose also includes disproportionate high-risk features for a normal API helper: persistent external webhook forwarding, Maton-hosted functions with injected account-scoped credentials, and local `--exec` handlers on untrusted event data. These data flows are openly disclosed rather than hidden, so this is not confirmed malware, but it is a medium/high-risk skill that centralizes credentials and enables ongoing automated data egress and actions beyond simple API calls.

Confidence: 90%Severity: 68%
AnomalyLOW
providers/claude/plugin/skills/api-gateway/references/box/README.md

No explicit malicious payload is evident in the shown Python snippet or the provided operational examples (no obfuscation, no covert execution, no system compromise behavior). However, the fragment provides powerful authenticated primitives to upload local file contents to a remote service and to change access controls and establish persistent webhooks that can forward event data to an external destination. The greatest security concern is abuse/misconfiguration risk (public shared links, attacker-controlled webhook targets, and permissions/deletion actions) rather than confirmed malware.

Confidence: 55%Severity: 58%
Audit Metadata
Analyzed At
Sep 5, 2026, 12:02 AM
Package URL
pkg:socket/skills-sh/maton-ai%2Fapi-gateway-skill%2Fapi-gateway%2F@bb129269d479ef4313546889222272d12a2b5d99
Security Audit — socket — api-gateway