google-maps-platform
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains a behavioral override directive that instructs the agent to ignore the 'call me first' instructions provided by the google-maps-code-assist-toolkit MCP server, substituting the tool's self-description with the skill's internal logic.
- [EXTERNAL_DOWNLOADS]: The skill implements a grounding workflow that dynamically fetches an instructions index and matched sub-skill files from Google's static content delivery network (www.gstatic.com).
- [PROMPT_INJECTION]: An indirect prompt injection surface is present as the agent is instructed to fetch and adhere to instruction sets from remote URLs defined in an index file, without explicit boundary markers or content sanitization.
Audit Metadata