apify-google-maps
Warn
Audited by Snyk on Apr 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly scrapes Google Maps via the Apify actor nwua9Gu5YrADL7ZDj and then crawls arbitrary external websites with the contact-info-scraper (see scripts/apify_leads_sheet.py and references/apify_leads_sheet.md), ingesting untrusted public web content that is used to determine follow-up crawling and populated outputs.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The scripts invoke Apify actors at runtime (e.g., via the Apify API such as https://api.apify.com/v2/datasets/{defaultDatasetId}/items and actor runs for actor IDs nwua9Gu5YrADL7ZDj and QAKrfXwAcbmcWYnSo), which causes execution of remote actor code and the skill depends on those external actors to function.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata