goplaces

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the goplaces utility via Homebrew from a third-party repository (steipete/tap/goplaces).
  • [COMMAND_EXECUTION]: The skill provides instructions for executing the goplaces binary with various flags to perform text searches, retrieve place details, and fetch reviews.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted content (such as place names and reviews) retrieved from the external Google Places API. This content is displayed to the user or processed by the agent without explicit sanitization mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 08:32 AM
Security Audit — agent-trust-hub — goplaces