Back to skill

Security audit

Google Maps Grounding MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Google Maps MCP setup guide, with expected API-key and npm dependency risks that users should handle carefully.

Before installing, treat GOOGLE_MAPS_API_KEY as a secret, avoid exposing it in shared terminals, logs, or screenshots, and understand where mcporter stores --system configuration. Install mcporter from a trusted npm registry, preferably pinned or in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned npm Dependency Allows Supply-Chain Compromise

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned third-party npm dependency
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"🗺️","requires":{"bins":["mcporter"],"env":["GOOGLE_MAPS_API_KEY"]},"primaryEnv":"GOOGLE_MAPS_API_KEY","install":[{"id":"node","kind":"node","package":"mcporter","bins":["mcporter"],"label":"Install mcporter (npm)"}]}}

Technical Analysis

The installation metadata identifies mcporter only by its npm package name and does not specify an exact audited version or package integrity hash. Consequently, dependency resolution can retrieve a mutable future release from the configured npm registry.

npm package installation may execute package lifecycle scripts. If the package, a maintainer account, or the package-distribution infrastructure is compromised, a malicious release could execute code during installation. This finding does not establish that the current mcporter package is malicious; it identifies the absence of controls that bind installation to a reviewed artifact.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or the dependency-distribution channel.
  2. The attacker publishes a malicious release under the expected mcporter package name.
  3. A user installs the Skill's required dependency using the unversioned installation declaration.
  4. npm resolves the mutable package reference to the malicious release.
  5. Malicious package code or lifecycle scripts execute with the privileges of the installation process.
  6. The payload may access files, environment variables, and network resources available to that process, potentially including GOOGLE_MAPS_API_KEY.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the dependency installation. The resulting scope is limited by that account's operating-system privileg ...[truncated 325 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin mcporter to an exact version that has been reviewed, rather than relying on an unversioned package reference.
  2. Use a lockfile and verify npm integrity metadata so installation resolves to a known artifact.
  3. Configure an explicitly trusted npm registry and enforce registry allowlisting where supported.
  4. Review the pinned package's source, transitive dependencies, provenance, and lifecycle scripts before distribution.
  5. Disable npm lifecycle scripts during installation when they are not required, for example through an appropriate ignore-scripts policy.
  6. Run dependency installation with a non-privileged account in an isolated environment and expose only the minimum necessary credentials.
  7. Add automated dependency monitoring, provenance verification, and controlled upgrade review so version changes cannot silently introduce unreviewed code.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to place a live API key directly into environment variables and reference it in shell commands, but provides no warning about shell history, process inspection, shared terminals, or persistent system-wide mcporter configuration. While this is common setup guidance, it can lead to accidental credential exposure if copied into logs, screenshots, shell history, or multi-user environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.