Back to skill

Security audit

Google Maps Scraper

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it uses unsafe raw shell examples with user-supplied search text and encourages collecting contact data without enough privacy or compliance guidance.

Review before installing. Use this only if you trust gmapsscraper.io with your searches and API key, and only collect contact data where you have a lawful and policy-compliant reason. Avoid running the documented curl examples with raw user-supplied text; use a JSON serializer or otherwise ensure search terms are treated strictly as data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:67
Finding

Shell Command Injection Through Unsafely Interpolated Search Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 67–75
Vulnerability Type: Shell command injection caused by unsafe template interpolation
Risk Level: High

bash
curl -X POST "https://gmapsscraper.io/api/v1/scrape" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \
  -d '{
    "keywords": ["{{keyword}} in {{location}}"],
    "email": true,
    "depth": 2
  }'

Technical Analysis

The keyword and location values are collected from the user and inserted directly into a single-quoted shell argument. No shell escaping, JSON-safe serialization, or input validation is specified.

A user-supplied apostrophe can terminate the single-quoted -d argument prematurely. Subsequent shell metacharacters in the substituted value may then be interpreted by the shell rather than treated as JSON data. JSON escaping alone would not be sufficient because shell parsing occurs before curl receives the request.

The API key is also present in the environment used by the vulnerable command. Consequently, successful command injection could allow an injected process to access that credential and other data available to the agent process.

Attack Path

  1. The agent asks the user to provide a business keyword and location.
  2. An attacker supplies a value containing an apostrophe followed by shell syntax and a harmless verification action, such as creating a marker file.
  3. The agent confirms the search and substitutes the attacker-controlled value into the documented command.
  4. The apostrophe closes the shell argument containing the JSON body.
  5. The shell interprets the remaining injected syntax as commands.
  6. Those commands execute with the same operating-system identity, environment, filesystem access, and network permissions as the agent.

Impact Assessment

Successful exploitation can provide arbitrary command execution under the agent's curr ...[truncated 553 chars]

Remediation
View remediation

Remediation Suggestions

Do not place template values directly into shell source. Construct the request with a JSON-aware serializer and pass the serialized body to curl through standard input:

bash
query="${keyword} in ${location}"

jq -n --arg query "$query" \
  '{keywords: [$query], email: true, depth: 2}' |
curl --fail-with-body --silent --show-error \
  -X POST "https://gmapsscraper.io/api/v1/scrape" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \
  --data-binary @-

Additional hardening measures:

  1. Prefer direct process invocation with an argument array rather than execution through a shell.
  2. Treat keyword and location exclusively as data and never evaluate or concatenate them into executable command text.
  3. Apply reasonable length limits and reject control characters. Input validation should supplement, not replace, safe serialization.
  4. Verify that jq is available and declare it as a required binary if the example above is adopted.
  5. Run the skill with least privilege, a restricted filesystem, and limited outbound network access.
  6. Keep the API key only in the environment, redact authorization headers from logs, and rotate the key if command injection may have occurred.
  7. Add regression tests using apostrophes, quotation marks, command substitutions, semicolons, newlines, and other shell metacharacters to confirm they remain literal JSON data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
## Get Started

1. Sign up free at https://gmapsscraper.io (5 searches included)
2. Get API key from dashboard
3. Set: `export GMAPS_SCRAPER_API_KEY=your_key`
4. Start scraping!

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill transmits user-provided search queries and the bearer API key to an external third-party service via curl. While external API use is expected for this skill, it is still a genuine security/privacy concern because business queries and extracted contact data are sent off-platform, and the documentation does not warn users about third-party data handling, logging, or trust boundaries.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
env:
        - GMAPS_SCRAPER_API_KEY
      bins:
        - curl
    primaryEnv: GMAPS_SCRAPER_API_KEY
    envVars:
      - name: GMAPS_SCRAPER_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly enables scraping of business contact data, including emails, and presents downstream lead-generation and cold-email use cases without any privacy, consent, or acceptable-use guidance. That creates a real compliance and misuse risk because users may collect and process personal/business contact data in ways that violate platform terms, anti-spam rules, or data-protection requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented advanced option specifies a fixed non-default language setting as an example without indicating that language should be chosen based on user preference. This can violate language/locale policy because it implicitly steers output to a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.