T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Shell Command Injection Through Unsafely Interpolated Export Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for exporting Google Maps business data, but its sample shell command can be unsafe with user-supplied search text and it sends/stores business contact data through a third-party service.
Review before installing. Use only with data you are allowed to export and process, understand that searches and results go through gmapsscraper.io, protect and rotate the API key if exposed, delete downloaded exports when no longer needed, and avoid using the provided shell snippets with unsanitized category or location text.
SKILL.md:62Shell Command Injection Through Unsafely Interpolated Export Parameters
The skill is designed to transmit user-specified search terms and retrieve exported business data from an external service using an API key, which is a real external data-transfer surface. In this context the behavior is intentional, but it still creates exposure around third-party sharing, API key handling, and local storage of downloaded contact data.
env:
- GMAPS_SCRAPER_API_KEY
bins:
- curl
primaryEnv: GMAPS_SCRAPER_API_KEY
envVars:
- name: GMAPS_SCRAPER_API_KEY
The skill handles and exports business contact information, including email addresses and phone numbers, and sends queries/results through a third-party service, yet it provides no clear privacy or data-handling warning. Users may not realize that contact data is being transmitted externally and stored locally, creating legal, confidentiality, and compliance exposure.
The trigger phrases are broad enough to match generic requests such as 'export', 'download', or 'save' Maps listings, which can cause the skill to activate outside a clearly scoped user intent. In practice this can lead to accidental scraping/export of third-party business data and unintended transmission to the external provider without sufficiently specific confirmation.
The skill explicitly encourages repurposing exported Google Maps business data for cold emails, lead scoring, and outreach, which goes beyond simple data export and materially increases privacy, compliance, and abuse risk. While not inherently malicious, this broadens the skill into lead-generation workflows using scraped contact data, raising the chance of spam, unauthorized profiling, or policy violations.
The request payload sets "lang": "en", which forces a specific language/locale behavior. The file does not indicate that this is optional, user-selected, or required for a region-specific purpose, so it conflicts with the policy against imposing a locale without opt-in.
No suspicious patterns detected.