google-maps-leads
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides structured instructions for the agent to use a browser tool to automate tasks such as navigating search results, scrolling to trigger lazy-loading of content, and clicking through to individual business listings.
- [EXTERNAL_DOWNLOADS]: The instructions guide the agent to access Google Maps and various external business websites. It also references an external proxy service provider for routing browser traffic.
- [PROMPT_INJECTION]: The skill involves scraping and processing data from external, untrusted websites, which presents an indirect prompt injection surface.
- Ingestion points: Business listing details from Google Maps and content from external business websites (e.g., contact and about pages).
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are included for the scraped content.
- Capability inventory: The agent uses a browser tool for navigation, interaction, and data extraction.
- Sanitization: No sanitization or validation of the scraped text is defined before processing.
Audit Metadata