google-maps

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the public npm registry to facilitate communication with Membrane's platform and Google Maps integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data received from the Google Maps API (e.g., place details, search results, directions). Maliciously crafted content within these external sources could attempt to influence the agent's logic if processed without adequate sanitization.
  • Ingestion points: Data returned by the membrane action run and membrane request commands is ingested into the agent's context.
  • Boundary markers: The provided instructions do not specify the use of delimiters or 'ignore' instructions for data processed from Google Maps.
  • Capability inventory: The skill allows the agent to execute CLI-based actions and arbitrary HTTP requests via the Membrane proxy.
  • Sanitization: No explicit sanitization or input validation logic for API responses is described in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 08:13 AM
Security Audit — agent-trust-hub — google-maps