Amap Dinner Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent Amap-based dinner planning helper that uses user-provided locations and an Amap API key for its stated mapping purpose.

Before installing, understand that addresses, meeting areas, and restaurant preferences you enter may be sent to Amap for geocoding, search, routing, and QR map generation. Use a scoped Amap API key if possible, and avoid entering highly sensitive private locations unless you are comfortable sharing them with Amap.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill processes sensitive location/address inputs and sends them to Amap's external Web Service API, but the user-facing usage and behavior sections do not present a clear upfront warning at the point of data entry. Although a later privacy section mentions transmission to Amap, this is easy to miss and insufficient for informed consent because precise location data can reveal home/work patterns and social relationships.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal