google-maps
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation for interacting with the fetcher-sh Google Maps API. It contains no executable code or scripts, which limits the potential for direct malicious behavior.\n- [DATA_EXFILTRATION]: The skill's network activity is confined to the official vendor domain
google-maps.fetcher.sh. This is consistent with the skill's purpose and the author's identity.\n- [CREDENTIALS_UNSAFE]: API keys shown in documentation are clearly marked as placeholders (e.g.,bby_live_xxxxxxxxxxxx). The skill follows security best practices by recommending that users store real keys in environment variables.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface area for indirect injection by processing user-supplied queries to fetch external data. However, the risk is minimal as the skill acts as a data retriever and provides examples using safe URL encoding for parameters.
Audit Metadata