apple-maps-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a local bash script
scripts/crawlora.shto make API requests. The script follows security best practices, such as validating the API key format, using a temporary configuration file for authentication to prevent process list exposure, and sanitizing input to prevent local file inclusion via curl's@syntax. - [EXTERNAL_DOWNLOADS]: The skill communicates with
api.crawlora.netto fetch map data. This is a vendor-owned resource used for the skill's primary functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Apple Maps (e.g., business names, descriptions, and user review snippets) which are potentially attacker-controlled and could contain malicious instructions.
- Ingestion points: External data is ingested from the Crawlora API via
scripts/crawlora.shin the form of business and place details. - Boundary markers: There are no specific instructions or delimiters provided in the skill to isolate the retrieved data from the agent's prompt context.
- Capability inventory: The skill allows the agent to make network requests through the helper script using curl.
- Sanitization: While outbound query parameters are URL-encoded by the script, the retrieved content from the API is not sanitized for potential injection patterns before being returned to the agent.
Audit Metadata