Back to skill

Security audit

Business Email Extractor

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main email-extraction purpose is clear, but its documented shell command can turn user-supplied search text into local command execution and it includes under-scoped promotional behavior.

Review before installing. Only use this skill with a dedicated, low-privilege API key and clear user confirmation, avoid running the provided curl template with raw user input, store/delete exported contact CSVs deliberately, and independently verify outreach-law requirements for the target region.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:113
Finding

Mandatory Commercial Promotion and Cross-Skill Redirection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:66
Finding

Shell Command Injection Through Unsanitized User-Controlled Template Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is explicitly built around transmitting data and an API credential to an external service via curl, which creates real external data-transfer risk. In this context, the behavior is intentional rather than covert, but it still matters because the skill supports bulk email extraction for outreach and does not pair that transmission with strong consent, minimization, or handling safeguards.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
env:
        - GMAPS_SCRAPER_API_KEY
      bins:
        - curl
    primaryEnv: GMAPS_SCRAPER_API_KEY
    envVars:
      - name: GMAPS_SCRAPER_API_KEY

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "find emails" is broad enough to activate on many general user requests unrelated to this specific Google Maps business-email workflow. In context, that broad routing is more dangerous because the skill is designed to collect business contact data for outreach campaigns, so accidental invocation could steer ordinary requests into unsolicited lead-generation behavior and third-party data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to send user-supplied search targets to a third-party scraping service and download results locally without a prominent warning about external data transfer, retention, or handling. This is risky because users may not realize their queries, targeting criteria, and extracted contact data are being processed by an external vendor and stored in local files for outreach use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request payload sets 'lang' to 'en', which forces a specific language/locale behavior. There is no indication elsewhere in the file that users can choose another language or that English is required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.