google-maps-search-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data retrieved from external Google Maps search results.
  • Ingestion points: scripts/google_maps_search_api.py fetches and prints business names, addresses, and review snippets from external sources via the BrowserAct API.
  • Boundary markers: The skill instructions do not define boundary markers or provide specific guidance to the agent to disregard potential instructions embedded in the extracted data.
  • Capability inventory: The skill executes a Python script (scripts/google_maps_search_api.py) capable of performing network requests and outputting large amounts of data to the agent's context.
  • Sanitization: There is no evidence of sanitization or filtering of the extracted text content before it is passed to the AI agent.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script to perform search and polling operations.
  • [EXTERNAL_DOWNLOADS]: The skill's Python script relies on the well-known requests library for communicating with the vendor's API endpoints at api.browseract.com.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — google-maps-search-api-skill