Back to skill

Security audit

Google Maps Api Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed BrowserAct Google Maps business-data scraper, with the main caution that searches and the API key are sent to BrowserAct.

Install this only if you intend to use BrowserAct for Google Maps data collection. Keep the BrowserAct API key in environment configuration rather than pasting it into chat, confirm before broad or recurring lead-generation searches, and consider privacy, compliance, and site terms before collecting phone numbers or other business contact data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill declares runtime requirements for an environment variable and executes a Python script that calls an external API, but it does not clearly declare corresponding permissions or provide an explicit data-flow warning. This creates a transparency and policy-enforcement gap: an agent may access secrets and transmit user-specified business data externally without a clearly bounded permission model.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says the agent should proactively trigger this skill for a very broad set of business-research tasks, which increases the chance of invocation without clear user intent or informed consent. In context, the skill sends search terms and may retrieve contact data via an external API, so overbroad triggering can lead to unnecessary third-party data transmission and surprising automation behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill markets collection of phone numbers, websites, addresses, ratings, and other business details through BrowserAct's Google Maps API, but it does not warn users that their search parameters and resulting data will be transmitted to an external provider. This omission undermines informed consent and can expose sensitive business-intelligence intent, especially for competitor research, lead generation, and bulk contact harvesting.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.