Back to skill

Security audit

Google Maps Leads

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its run instructions use a risky shell command template and send lead-search data to an outside service with limited privacy and compliance guidance.

Review generated commands before running them, protect the GMAPS_SCRAPER_API_KEY, and avoid using untrusted or oddly formatted search terms unless the payload is built with a proper JSON encoder instead of raw shell substitution. Only install if you are comfortable sending targeting criteria and lead/contact data to gmapsscraper.io, and make sure any outreach complies with applicable privacy and anti-spam rules.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:75
Finding

Shell Command Injection Through Unescaped Search Parameters

Content
View full analysis
/tmp/gmaps-skill-poc; # ``` 3. The agent substitutes this value directly into `{{industry}}`. 4. The injected single quote closes the shell's `-d` argument. 5. The semicolon begins a new shell command, c ...[truncated 1197 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill requires curl and an external API key, indicating intentional data transmission to a third-party service. External transmission is expected for this skill, but it still presents a real security concern because user-provided search criteria and retrieved lead data will leave the local system, and the skill does not clearly communicate those trust boundaries or key-handling expectations.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
env:
        - GMAPS_SCRAPER_API_KEY
      bins:
        - curl
    primaryEnv: GMAPS_SCRAPER_API_KEY
    envVars:
      - name: GMAPS_SCRAPER_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is explicitly designed to extract business contact details, score them for outreach, and produce outreach-ready lead lists, but it provides no guidance on privacy, consent, data minimization, or compliance with anti-spam and marketing laws. This creates a realistic risk that users will collect and use personal or contact data in ways that violate policy, contractual restrictions, or local regulations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to send search keywords, industry targeting, location criteria, and an API credential to a third-party service via curl, but it does not disclose that this information leaves the local environment or may be logged and processed by that provider. Users may unknowingly transmit sensitive market intelligence, customer targeting plans, or regulated data to an external processor.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The request payload sets "lang": "en", which forces a specific language/locale in the skill behavior. The file does not present this as an opt-in choice or explain why English is required for this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.