gmaps-leads

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from arbitrary websites to extract lead data, which can lead to indirect prompt injection attacks.
  • Ingestion points: External website content is fetched in scripts/extract_website_contacts.py via fetch_page and converted to markdown.
  • Boundary markers: The model prompt in scripts/extract_website_contacts.py (lines 211-255) uses a simple WEBSITE CONTENT: header without robust delimiters or instructions to ignore embedded commands within the ingested text.
  • Capability inventory: The skill possesses the capability to write data to Google Sheets via gspread and perform additional network requests relative to business enrichment.
  • Sanitization: The skill uses html2text to strip HTML tags, which provides basic cleanup but does not sanitize potential malicious natural language instructions that might be present in the visible text of a webpage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:43 PM