google-maps-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled shell script scripts/crawlora.sh to interface with the Crawlora API. The script implements strict security controls, including path whitelisting using anchored regular expressions and a blacklist of characters (?, #, %, .., //) to prevent path traversal or smuggling. It also uses curl securely by passing parameters via --data-urlencode and the request body via stdin, avoiding shell interpretation and preventing local file disclosure via the @ prefix.
  • [CREDENTIALS_UNSAFE]: The skill requires a CRAWLORA_API_KEY. The implementation follows security best practices by reading the key from the environment and passing it to curl through a temporary configuration file created with mktemp and restricted permissions (chmod 600). This ensures the secret is not visible in the process list and is automatically removed by a trap on exit.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Google Maps (place reviews and descriptions). Mandatory Evidence Chain: (1) Ingestion points: JSON responses from api.crawlora.net processed in scripts/crawlora.sh. (2) Boundary markers: Absent in instructions. (3) Capability inventory: Network requests and file writes (temporary config). (4) Sanitization: The helper script prevents argument injection and file disclosure via specific curl flags and input filtering.
  • [EXTERNAL_DOWNLOADS]: The skill connects to https://api.crawlora.net/api/v1 to retrieve map data. This is a vendor-owned resource associated with the skill author (crawlora-org) and is used for its intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — google-maps-research