mcp-google-map-project
Warn
Audited by Snyk on Mar 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's runtime tools explicitly call public Google APIs (notably the Places API (New) searchText and place details endpoints, plus Routes/Weather/AirQuality REST APIs) to ingest live, potentially user-generated place data which the agent is required to read and use to drive tool chaining and decisions (see SKILL.md and references/google-maps-api-guide.md).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata