Back to skill

Security audit

Local Business Finder

Security checks for vulnerabilities and agentic risk

Overview

The skill's business-search purpose is coherent, but its documented shell command can be unsafe if user-provided search text is inserted literally.

Review before installing. Use this only if you are comfortable sending business search queries to gmapsscraper.io with your API key, and avoid executing the shown curl command by literal text substitution; values should be JSON-encoded and passed to curl without shell interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:67
Finding

Shell Command Injection Through Unescaped User-Controlled Template Values

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 67-76
Vulnerability Type: Shell command injection caused by unsafe textual interpolation
Risk Level: High

Vulnerable Code

bash
curl -X POST "https://gmapsscraper.io/api/v1/jobs" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \
  -d '{
    "name": "Find: {{business_type}} in {{location}}",
    "keywords": ["{{business_type}} in {{location}}"],
    "lang": "en",
    "depth": 2,
    "email": true
  }'

Technical Analysis

The business_type and location template variables originate from the user's request and are interpolated directly into a shell command. They appear inside a single-quoted shell argument without shell-safe or JSON-safe encoding.

If an agent performs literal template substitution and executes the resulting command through a shell, a value containing a single quote can terminate the -d argument. The remaining characters may then be interpreted as shell operators and commands rather than JSON data. JSON escaping alone is insufficient because shell parsing occurs before curl receives the request body.

This vulnerability is conditional on the documented command being instantiated through direct textual substitution and executed by a shell, which is the workflow shown by the Skill.

Attack Path

  1. An attacker supplies a crafted business type or location containing a single quote, shell separators, and an appended command.
  2. The agent parses the attacker-controlled text as business_type or location.
  3. The agent substitutes that value literally into the documented curl command.
  4. The injected single quote closes the intended shell argument prematurely.
  5. The shell parses the remaining attacker-controlled text as command syntax.
  6. The appended command executes locally with the privileges and environment of the agent process.

Impact Assessme

...[truncated 773 chars]

Remediation
View remediation

Remediation Suggestions

Avoid direct textual interpolation of user-controlled values into shell commands.

  1. Construct the request in a programming language using a standard JSON serializer.
  2. Invoke the HTTP client without a shell, passing each argument separately through a process API.
  3. If a shell example must be retained, use jq to serialize values safely and pass user input through positional arguments or environment variables rather than embedding it into shell source.
  4. Validate business_type and location against reasonable length and character constraints as defense in depth. Validation must not replace context-appropriate encoding.
  5. Store the generated JSON in a securely created temporary file or pipe it directly to curl; avoid predictable temporary filenames.
  6. Add tests covering single quotes, double quotes, backslashes, command separators, command substitutions, newlines, and malformed JSON.

A safer shell pattern is:

bash
payload="$(
  jq -n \
    --arg business_type "$BUSINESS_TYPE" \
    --arg location "$LOCATION" \
    '{
      name: ("Find: " + $business_type + " in " + $location),
      keywords: [($business_type + " in " + $location)],
      lang: "en",
      depth: 2,
      email: true
    }'
)" || exit 1

curl --fail-with-body -X POST "https://gmapsscraper.io/api/v1/jobs" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \
  --data-binary "$payload"

In this pattern, values are treated as data by jq rather than being inserted into executable shell syntax.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase "Find any local business by category and location" is very broad and the examples include generic user language like finding restaurants, dentists, or services. Without tighter trigger constraints or exclusion examples, this could cause unintended invocation on ordinary location-search requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Entries such as "User wants to find businesses near a location" and "User is researching a local market" are broad intents that overlap with common conversational requests. The file does not define exclusions, required specificity, or a constrained invocation context to distinguish appropriate from inappropriate activation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill instructs the agent to transmit user-provided search terms and an API credential to a third-party service, creating a real data egress boundary. Even though this is the intended functionality, external transmission is security-relevant because sensitive user queries, business targeting activity, and account-linked usage metadata are sent off-platform without any explicit privacy, minimization, or consent safeguards beyond credit confirmation.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

Step 4: Execute Search

bash
curl -X POST "https://gmapsscraper.io/api/v1/jobs" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \
  -d '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The payload sets "lang": "en", which forces a specific language/locale behavior. There is no indication elsewhere in the file that users can choose a language or that English-only operation is required for a documented reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.