Back to skill

Security audit

Google Maps Export

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for exporting Google Maps business data, but its sample shell command can be unsafe with user-supplied search text and it sends/stores business contact data through a third-party service.

Review before installing. Use only with data you are allowed to export and process, understand that searches and results go through gmapsscraper.io, protect and rotate the API key if exposed, delete downloaded exports when no longer needed, and avoid using the provided shell snippets with unsanitized category or location text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:62
Finding

Shell Command Injection Through Unsafely Interpolated Export Parameters

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill is designed to transmit user-specified search terms and retrieve exported business data from an external service using an API key, which is a real external data-transfer surface. In this context the behavior is intentional, but it still creates exposure around third-party sharing, API key handling, and local storage of downloaded contact data.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
env:
        - GMAPS_SCRAPER_API_KEY
      bins:
        - curl
    primaryEnv: GMAPS_SCRAPER_API_KEY
    envVars:
      - name: GMAPS_SCRAPER_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill handles and exports business contact information, including email addresses and phone numbers, and sends queries/results through a third-party service, yet it provides no clear privacy or data-handling warning. Users may not realize that contact data is being transmitted externally and stored locally, creating legal, confidentiality, and compliance exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match generic requests such as 'export', 'download', or 'save' Maps listings, which can cause the skill to activate outside a clearly scoped user intent. In practice this can lead to accidental scraping/export of third-party business data and unintended transmission to the external provider without sufficiently specific confirmation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly encourages repurposing exported Google Maps business data for cold emails, lead scoring, and outreach, which goes beyond simple data export and materially increases privacy, compliance, and abuse risk. While not inherently malicious, this broadens the skill into lead-generation workflows using scraped contact data, raising the chance of spam, unauthorized profiling, or policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request payload sets "lang": "en", which forces a specific language/locale behavior. The file does not indicate that this is optional, user-selected, or required for a region-specific purpose, so it conflicts with the policy against imposing a locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.