Back to skill

Security audit

Google Maps Api Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it asks users to provide an API key through the agent and broadly encourages automated business-contact scraping, so it needs review before installation.

Install only if you are comfortable with the agent running Google Maps data extraction through BrowserAct. Configure BROWSERACT_API_KEY as an environment secret rather than pasting it into chat, and verify that scraping, storing, and using business contact data for outreach or CRM import is allowed by your laws, platform terms, and organization policy.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

Insecure Solicitation of BrowserAct API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-29; scripts/google_maps_api.py:94-97
Vulnerability Type: Credential exposure through insecure user instructions
Risk Level: Medium

Vulnerable Code

SKILL.md:27-29:

markdown
Before running, check the `BROWSERACT_API_KEY` environment variable. If not set, do not take other measures; ask and wait for the user to provide it.
**Agent must inform the user**:
> "Since you haven't configured the BrowserAct API Key, please visit the [BrowserAct Console](https://www.browseract.com/reception/integrations) to get your Key."

scripts/google_maps_api.py:94-97:

python
print("Please follow these steps:", flush=True)
print("1. Go to: https://www.browseract.com/reception/integrations", flush=True)
print("2. Copy your API Key.", flush=True)
print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)

Technical Analysis

The Skill explicitly directs users to provide a BrowserAct API key to the Agent as an alternative to configuring it locally. This violates least-exposure principles because the script only requires the credential through the BROWSERACT_API_KEY environment variable; the Agent does not need to receive the plaintext value in a conversation.

A credential submitted through chat can enter conversation history, Agent context, application telemetry, diagnostic logs, or other retained records. Although the script itself places the key only in an HTTPS authorization header and does not print it, the surrounding instructions create a separate credential-disclosure path before execution.

Attack Path

  1. The Skill detects that BROWSERACT_API_KEY is not configured.
  2. The user is instructed to obtain and provide the API key to the Agent.
  3. The user pastes the plaintext key into the conversation.
  4. The key may be retained in chat history, Agent context, telemetry, or logs.
  5. A part ...[truncated 619 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions telling users to provide an API key to the Agent or through chat.
  2. Require users to configure BROWSERACT_API_KEY directly in the execution environment.
  3. Recommend a local secret manager, protected environment configuration, or platform-provided secret storage.
  4. Replace the current message with guidance that explicitly warns users not to paste credentials into conversations.
  5. Ensure the Agent never echoes, logs, persists, or requests the plaintext key.
  6. If a key has already been disclosed through chat, advise the user to revoke and rotate it.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/google_maps_api.py:31
Finding

Unbounded HTTP Requests and Task Polling

Content
View full analysis

Vulnerability Details

File Location: scripts/google_maps_api.py:31, scripts/google_maps_api.py:49-73
Vulnerability Type: Missing network timeouts and unbounded polling
Risk Level: Low

Vulnerable Code

python
res = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers).json()
python
# 2. Poll for Completion
while True:
    try:
        status_res = requests.get(f"{API_BASE_URL}/get-task-status?task_id={task_id}", headers=headers).json()
        status = status_res.get("status")
        
        timestamp = datetime.datetime.now().strftime("%H:%M:%S")
        print(f"[{timestamp}] Task Status: {status}", flush=True)
        
        if status == "finished":
            print(f"[{timestamp}] Task finished successfully.", flush=True)
            break
        elif status in ["failed", "canceled"]:
            print(f"Error: Task {status}. Please check your BrowserAct dashboard.", flush=True)
            return None
    except Exception as e:
        timestamp = datetime.datetime.now().strftime("%H:%M:%S")
        print(f"[{timestamp}] Polling error: {e}. Retrying...", flush=True)
        
    time.sleep(10)

# 3. Get Results
try:
    task_info = requests.get(f"{API_BASE_URL}/get-task?task_id={task_id}", headers=headers).json()

Technical Analysis

None of the HTTP operations specify connection or read timeouts. A remote endpoint that accepts a connection but does not complete its response can therefore block execution for an implementation-dependent and potentially prolonged period.

The polling loop is also unconditional and has no overall deadline or maximum attempt count. Exceptions are caught and retried indefinitely, while unexpected or missing status values remain nonterminal. Consequently, a stalled service, persistent network failure, or task that never reaches finished, failed, or canceled can prevent the Skill ...[truncated 1143 chars]

Remediation
View remediation

Remediation Suggestions

  1. Configure explicit connection and read timeouts for every request, for example timeout=(5, 30).
  2. Call raise_for_status() before parsing response JSON.
  3. Add an overall task deadline based on monotonic time.
  4. Enforce a maximum number of polling attempts.
  5. Treat missing or unknown task statuses as bounded errors rather than polling forever.
  6. Replace indefinite exception retries with bounded exponential backoff and optional jitter.
  7. Return a clear failure result when the deadline or retry limit is reached.
  8. Consider using a configured requests.Session so timeout and retry policies are applied consistently.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/google_maps_api.py (reported line 85)May include surrounding context.

python
return None

if __name__ == "__main__":
    # Get API key from environment variable
    api_key = os.getenv("BROWSERACT_API_KEY")
    
    if len(sys.argv) < 2:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a Python script that uses an API key and performs networked scraping, but it does not declare an explicit tool scope such as allowed tools or permissions. This weakens policy boundaries for the agent and can lead to execution in contexts where users and platforms are not clearly informed that environment secrets and outbound network access are required.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says the agent should proactively trigger this skill for a very broad set of business-research and lead-generation tasks. That can cause unintended invocation without clear user intent, leading to unnecessary scraping, collection of business contact data, and use of paid external API calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promotes collecting phone numbers, website links, reviews, and CRM-sync use cases, but it does not warn users that it performs contact-data collection and may support outreach workflows. This reduces transparency and increases the risk of privacy, compliance, or acceptable-use issues, especially when used for bulk lead generation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/google_maps_api.py (reported line 15)May include surrounding context.

python
# API Configuration
TEMPLATE_ID = "77577579210625331"
API_BASE_URL = "https://api.browseract.com/v2/workflow"

def run_google_maps_task(api_key, keywords, language="en", country="us"):
    headers = {"Authorization": f"Bearer {api_key}"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/google_maps_api.py (reported line 31)May include surrounding context.

python
# 1. Start Task
    print(f"Start Task", flush=True)
    try:
        res = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers).json()
    except Exception as e:
        print(f"Error: Connection to API failed - {e}", flush=True)
        return None

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function signature sets default values of language="en" and country="us", which imposes a specific language/locale when the user does not provide overrides. This is a natural-language policy concern because the script silently defaults to a locale rather than offering an explicit choice or documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.