gmaps-leads
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from arbitrary websites to extract lead data, which can lead to indirect prompt injection attacks.
- Ingestion points: External website content is fetched in
scripts/extract_website_contacts.pyviafetch_pageand converted to markdown. - Boundary markers: The model prompt in
scripts/extract_website_contacts.py(lines 211-255) uses a simpleWEBSITE CONTENT:header without robust delimiters or instructions to ignore embedded commands within the ingested text. - Capability inventory: The skill possesses the capability to write data to Google Sheets via
gspreadand perform additional network requests relative to business enrichment. - Sanitization: The skill uses
html2textto strip HTML tags, which provides basic cleanup but does not sanitize potential malicious natural language instructions that might be present in the visible text of a webpage.
Audit Metadata