google-maps-search-api-skill

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a Google Maps search/scraping automation that delegates data collection to a third-party service (BrowserAct). Functionally it matches its stated purpose (search keywords -> structured business data). The primary risks are supply-chain and privacy-related: forwarding search queries and the BROWSERACT_API_KEY to a third-party scraping provider concentrates trust and exposes collected PII if the provider is malicious or compromised; automated scraping may also run afoul of Google Maps terms of service. There is no evidence of obfuscation, embedded malware, or direct credential theft in the skill text itself. Recommend: (1) treat the BrowserAct service as a high-trust dependency — verify its reputation, security, and privacy policies before supplying API keys; (2) document and implement safeguards for PII handling and TOS compliance; (3) require explicit user consent before running automated extraction, and avoid proactive runs without user confirmation.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/browser-act%2Fskills%2Fgoogle-maps-search-api-skill%2F@1d40737c635cbeadbb6d0336d56acfa3c7e6f52b