google-maps-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a bundled shell script
scripts/crawlora.shto interface with the Crawlora API. The script implements strict security controls, including path whitelisting using anchored regular expressions and a blacklist of characters (?,#,%,..,//) to prevent path traversal or smuggling. It also usescurlsecurely by passing parameters via--data-urlencodeand the request body via stdin, avoiding shell interpretation and preventing local file disclosure via the@prefix. - [CREDENTIALS_UNSAFE]: The skill requires a
CRAWLORA_API_KEY. The implementation follows security best practices by reading the key from the environment and passing it tocurlthrough a temporary configuration file created withmktempand restricted permissions (chmod 600). This ensures the secret is not visible in the process list and is automatically removed by atrapon exit. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Google Maps (place reviews and descriptions). Mandatory Evidence Chain: (1) Ingestion points: JSON responses from
api.crawlora.netprocessed inscripts/crawlora.sh. (2) Boundary markers: Absent in instructions. (3) Capability inventory: Network requests and file writes (temporary config). (4) Sanitization: The helper script prevents argument injection and file disclosure via specificcurlflags and input filtering. - [EXTERNAL_DOWNLOADS]: The skill connects to
https://api.crawlora.net/api/v1to retrieve map data. This is a vendor-owned resource associated with the skill author (crawlora-org) and is used for its intended purpose.
Audit Metadata