Back to skill

Security audit

Google Maps Extractor (Apify)

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles an Apify credential and contact-scraping workflows with enough supply-chain and privacy weaknesses that users should review it carefully.

Install only if you are comfortable giving this skill an Apify token and sending search targets, Maps URLs, place IDs, and optional contact-enrichment inputs to Apify. Prefer a least-privilege Apify token, set small budgets, avoid passing tokens on the command line, pin installer/source versions where possible, and use contact enrichment only for lawful, consent-aware, anti-spam-compliant workflows with clear retention limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:162
Finding

Unpinned Remote Installer and Mutable Skill Source

Content
View full analysis
Remediation
View remediation
add ... ``` 2. Pin the installed repository content to an immutable commit SHA or signed release tag if supported by the installer. 3. Publish and document expected commit identifiers and checksums for released skill artifacts. 4. Recommend installation with npm lifecycle scripts disabled where compatible: ```bash npm_config_ignore_scripts=true npx skills@ ... ``` 5. Verify the npm package publisher, provenance, and integrity before recommending a new version. 6. Require review of repository changes before updating the documented commit or release. 7. Avoid automatic confirmation flags such as `-y` in security-sensitive installation guidance unless the exact package and source revision are pinned. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/google_maps_extractor_actor.py:220
Finding

Apify API Token Transmitted in URL Query String

Content
View full analysis
dict[str, Any]: params: dict[str, str | int | float] = { "token": token, "timeout": timeout_sec, "clean": "true", } if budget_usd is not None: if budget_usd <= 0: raise SkillError("--budget-usd must be > 0.") params["maxTotalChargeUsd"] = budget_usd url = ( f"https://api.apify.com/v2/acts/{urllib.parse.quote(actor_id, safe='')}/run-sync-get-dataset-items" f"?{urllib.parse.urlencode(params)}" ) body = json.dumps(payload).encode("utf-8") req = urllib.request.Request( url=url, data=body, headers={"Content-Type": "application/json"}, method="POST", ) try: with urllib.request.urlopen(req, timeout=min(timeout_sec + 30, 3600)) as response: ``` ### Technical Analysis The script correctly sends requests over HTTPS to the declared Apify API, and transmitting an Apify credential to that service is necessary for the Skill's advertised functionality. However, the token is placed in the URL query string as `token=`. Sensitive values in URLs are more likely to be retained than equivalent authorization headers. Full request URLs may be captured by application logs, API gateway logs, debugging tools, observability systems, proxy logs, exception telemetry, or endpoint access logs. HTTPS protects the URL from ordinary passive network observers while it is in transit, but it does not prevent URL retention by the client, TLS-terminating infrastructure, or the destination service. The code does not deliberately print the token, and no hidden exfiltration destination was found. The weakn ...[truncated 1368 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
7. Run `scripts/google_maps_extractor_actor.py` or call the Apify API directly.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
AI-agent skill for running a production Google Maps Extractor through Apify. It helps agents create correct payloads, control budget, run the actor, and return structured Google Maps place and business data for local lead generation, local SEO, competitor research, directory building, store locator datasets, and CRM enrichment.

![Real Google Maps search results for bike repair shops in Portland](https://api.apify.com/v2/key-value-stores/RgWfy9bTkPpSqNzrV/records/google-maps-extractor-real-google-maps.png?signature=1c5HpULMOkoXKSytZxW0G)

Default actor:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README promotes contact enrichment, CRM enrichment, and business data collection workflows but does not clearly warn about privacy, lawful basis, consent expectations, or downstream handling of personal data that may be collected from public websites. In an agent context, this increases the chance of over-collection or inappropriate processing of emails, phones, and contact details at scale.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares access to environment variables, file reads, and network-reachable behavior, but does not define an explicit tool scope such as allowed-tools or permissions. This weakens least-privilege controls and can let an agent invoke the skill with broader capabilities than reviewers or orchestrators expect, especially since the skill consumes a secret token and performs external API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly supports extracting public website contacts and building lead lists, but it provides no privacy, consent, anti-spam, or jurisdictional compliance guidance. In practice, this can facilitate large-scale collection and downstream use of personal or business contact data in ways that violate platform policies, privacy laws, or anti-spam rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The contract explicitly supports scraping public business websites for emails, phone numbers, and social profiles, but it provides no privacy, consent, or acceptable-use warning. Even if the data is publicly accessible, this feature materially increases the ability to collect and aggregate contact data at scale, which can enable spam, profiling, or regulatory noncompliance if used without constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends user-supplied queries, URLs, place IDs, and optional enrichment inputs to Apify, a third-party service, but provides no explicit user-facing disclosure or consent step at the point of transmission. In a data-extraction skill, this can expose potentially sensitive business targets, search intent, or embedded personal/contact data to an external processor without the user's clear awareness.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The code performs an outbound HTTPS request to Apify and includes the full JSON payload in the request body, which constitutes external data transmission. In this skill's context, the transmission is core functionality, but it still matters because user-entered search terms, URLs, place IDs, and optional contact-enrichment inputs are exported to a third party and could include sensitive or proprietary targeting data.

Content

Scanner excerpt · scripts/google_maps_extractor_actor.py (reported line 232)May include surrounding context.

python
params["maxTotalChargeUsd"] = budget_usd

    url = (
        f"https://api.apify.com/v2/acts/{urllib.parse.quote(actor_id, safe='')}/run-sync-get-dataset-items"
        f"?{urllib.parse.urlencode(params)}"
    )
    body = json.dumps(payload).encode("utf-8")

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructs use of the language parameter for normal search, and later examples set "language": "en" in recommended inputs. This nudges the skill toward a fixed locale without documenting that language should be chosen based on user preference or task context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sample payload for local business discovery explicitly sets language to English, which can bias results toward a specific locale/language absent user request. The file does not explain that this is only an example or advise selecting language based on user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exact-URLs sample hard-codes English as the language setting, which is a locale choice not tied to stated user preference. Without an explicit rationale or opt-in, this conflicts with the requirement to avoid forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The payload normalization sets language to en by default, which imposes a specific locale when the user does not choose one. The policy requires avoiding forced language or locale selection unless the user is given a choice or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.