api-gateway

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is largely consistent with a cloud-based API gateway concept that uses a MATON_API_KEY to authorize per-service OAuth-enabled gateway operations. The data flows and credential model are appropriate for such a gateway, but the central MATON_API_KEY represents a high-value secret and introduces a significant trust-centralization risk. Operational safeguards are essential: enforce strict access controls, minimize logging of secrets, secure storage for MATON_API_KEY, enforce TLS/audit trails for ctrl.maton.ai and gateway.maton.ai interactions, and implement per-connection scoping/least privilege. While no malicious activity is evident in this fragment, its architecture warrants thorough threat modeling and secure deployment practices to prevent credential leakage and ensure data privacy across multiple external services.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fapi-gateway%2F@c969d6304e7eec9524d22c91acfc760214a66031