This skill grants broad access to sensitive external APIs and
Claims to do
API Gateway: Passthrough proxy for direct access to third-party APIs using managed OAuth connections, provided by [Maton](https://maton.ai). The API gateway lets you call native API endpoints directly.
Actually does
This skill acts as an API gateway, proxying HTTP GET, POST, PUT, PATCH, and DELETE requests to over 100 third-party APIs (e.g., Slack, HubSpot, Google Sheets, Salesforce, Notion, Stripe) via `https://gateway.maton.ai`. It uses a `MATON_API_KEY` for authentication to Maton and manages OAuth connections to these services through `https://ctrl.maton.ai`, allowing users to list, create, get, and delete connections.
openclaw skills install byungkyu/api-gatewayThe skill provides a gateway to over 100 external APIs, many of which handle highly sensitive data (e.g., financial, personal, business-critical). A compromised or misdirected agent could leverage this broad access to cause significant data exfiltration, financial actions, or data destruction.
Supported Services table listing 100+ APIs
The skill exposes endpoints for an agent to programmatically create, list, retrieve, and delete connections to external services. This capability, while legitimate, could be abused by a malicious agent to create excessive connections, delete critical ones, or manage access without explicit user confirmation.
https://ctrl.maton.ai/connections (POST, GET, DELETE)
[](https://mondoo.com/ai-agent-security/skills/clawhub/byungkyu/api-gateway)<a href="https://mondoo.com/ai-agent-security/skills/clawhub/byungkyu/api-gateway"><img src="https://mondoo.com/ai-agent-security/api/badge/clawhub/byungkyu/api-gateway.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/clawhub/byungkyu/api-gateway.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.