api-gateway
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a legitimate API gateway for connecting to various external services. All primary network operations point to the vendor's own infrastructure at gateway.maton.ai and ctrl.maton.ai.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest data from numerous external platforms (e.g., Slack messages, Notion pages, Jira issues) into the agent context. 1. Ingestion points: External API responses from 100+ integrated services (SKILL.md). 2. Boundary markers: Absent from the documented instructions. 3. Capability inventory: Network operations via the Maton gateway. 4. Sanitization: Not explicitly defined in the skill documentation.
Audit Metadata