google-my-business

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the official Membrane CLI from the NPM registry to manage business integrations.
  • [COMMAND_EXECUTION]: Utilizes the membrane command-line tool to perform administrative tasks, authenticate users, and interact with the Google My Business API.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Google My Business (such as user reviews and questions) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Data is retrieved through actions like list-questions, list-answers, and location metadata in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are provided for the data being processed.
  • Capability inventory: The skill can execute business actions and perform network requests via membrane action run and membrane request.
  • Sanitization: There is no evidence of content filtering or sanitization for the data retrieved from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:56 PM
Security Audit — agent-trust-hub — google-my-business