google-maps

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation for interacting with the fetcher-sh Google Maps API. It contains no executable code or scripts, which limits the potential for direct malicious behavior.\n- [DATA_EXFILTRATION]: The skill's network activity is confined to the official vendor domain google-maps.fetcher.sh. This is consistent with the skill's purpose and the author's identity.\n- [CREDENTIALS_UNSAFE]: API keys shown in documentation are clearly marked as placeholders (e.g., bby_live_xxxxxxxxxxxx). The skill follows security best practices by recommending that users store real keys in environment variables.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface area for indirect injection by processing user-supplied queries to fetch external data. However, the risk is minimal as the skill acts as a data retriever and provides examples using safe URL encoding for parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:22 PM
Security Audit — agent-trust-hub — google-maps