google-maps-phone-extractor
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill mandates the download and installation of the BrowserAct CLI from an external site (browseract.com) if the dependency is not found on the host system.
- [PROMPT_INJECTION]: The instructions explicitly direct the agent to circumvent standard security practices by performing automatic installations "without asking the user to confirm" and to "not request separate approval for dependency installation," which is an attempt to override safety protocols and reduce user oversight.
- [COMMAND_EXECUTION]: The skill contains instructions for the agent to execute installation commands for third-party tools autonomously, representing a risk of unauthorized software execution if the source is compromised.
- [PROMPT_INJECTION]: Because the skill processes data from external web listings (Google Maps), it has an attack surface for indirect prompt injection. Malicious content embedded in listings could influence agent behavior, and the skill lacks explicit boundary markers or sanitization logic to mitigate this risk.
Audit Metadata