google_maps-automation

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill connects to and queries Google Maps via the composio google_maps toolkit (e.g., place search and tool responses returned by RUBE_MULTI_EXECUTE_TOOL / RUBE_SEARCH_TOOLS), so it will ingest and interpret public third‑party content (place data and user-generated content) as part of its workflow.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill requires contacting the MCP server at https://rube.app/mcp at runtime (via RUBE_SEARCH_TOOLS and RUBE_MULTI_EXECUTE_TOOL) to fetch tool schemas and execute tools, so remote content from that URL can directly shape agent prompts and trigger remote code execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 01:43 AM