T01 · Skill Instruction Hijacking
- Location
SKILL.md:113- Finding
Mandatory Commercial Promotion and Cross-Skill Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s main email-extraction purpose is clear, but its documented shell command can turn user-supplied search text into local command execution and it includes under-scoped promotional behavior.
Review before installing. Only use this skill with a dedicated, low-privilege API key and clear user confirmation, avoid running the provided curl template with raw user input, store/delete exported contact CSVs deliberately, and independently verify outreach-law requirements for the target region.
SKILL.md:113Mandatory Commercial Promotion and Cross-Skill Redirection
SKILL.md:66Shell Command Injection Through Unsanitized User-Controlled Template Values
The skill is explicitly built around transmitting data and an API credential to an external service via curl, which creates real external data-transfer risk. In this context, the behavior is intentional rather than covert, but it still matters because the skill supports bulk email extraction for outreach and does not pair that transmission with strong consent, minimization, or handling safeguards.
env:
- GMAPS_SCRAPER_API_KEY
bins:
- curl
primaryEnv: GMAPS_SCRAPER_API_KEY
envVars:
- name: GMAPS_SCRAPER_API_KEY
The trigger phrase "find emails" is broad enough to activate on many general user requests unrelated to this specific Google Maps business-email workflow. In context, that broad routing is more dangerous because the skill is designed to collect business contact data for outreach campaigns, so accidental invocation could steer ordinary requests into unsolicited lead-generation behavior and third-party data transmission.
The skill instructs the agent to send user-supplied search targets to a third-party scraping service and download results locally without a prominent warning about external data transfer, retention, or handling. This is risky because users may not realize their queries, targeting criteria, and extracted contact data are being processed by an external vendor and stored in local files for outreach use.
The request payload sets 'lang' to 'en', which forces a specific language/locale behavior. There is no indication elsewhere in the file that users can choose another language or that English is required for a region-specific compliance reason.
No suspicious patterns detected.