Back to skill

Security audit

Baidu Map Android SDK(百度地图官方安卓 SKills)

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for Baidu Map Android SDK integration; its location and network guidance is expected for mapping apps and is mostly disclosed.

Before installing, be aware that this skill is written in Chinese and is focused on Baidu's Android mapping ecosystem. Generated app code may request location and create shareable map links, so developers should add clear user consent, request only needed permissions, avoid unnecessary background/live location collection, and confirm what exact location data is shared.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains the skill description, usage conditions, and operating rules only in Chinese, which effectively forces a specific language for users of the skill. The policy allows locale constraints only when the skill offers a language choice or clearly documents a justified region-specific limitation, which is not stated here.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/class-reference.md (reported line 66)May include surrounding context.

md
## 室内图

- `BaiduMap.setOnBaseIndoorMapListener`、`switchBaseIndoorMapFloor`、MapBaseIndoorMapInfo、SwitchFloorError

## 投影与 3D Marker

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/overview.md (reported line 70)May include surrounding context.

md
## 室内图

- `BaiduMap.setOnBaseIndoorMapListener`、`switchBaseIndoorMapFloor`、MapBaseIndoorMapInfo、SwitchFloorError

## 投影与 3D Marker

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill document is written in Chinese and does not indicate that other languages are available or that Chinese is a region-specific requirement. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs developers to enable location collection, configure a LocationClient, and continuously receive coordinates, but it does not mention runtime permission prompts, user consent, data minimization, or privacy disclosure obligations. In an Android location-integration skill, this omission can lead downstream developers to implement background or repeated location tracking without adequate user-facing notice, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs developers to generate and share short URLs for precise locations, POIs, and routes, but it does not warn that these links may disclose sensitive location data to unintended recipients or third-party services. In an Android mapping SDK integration context, this omission can lead to privacy violations if apps expose user or device location without clear consent, minimization, or access controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, beginning with the title and continuing throughout the reference. Under the policy rule for language or locale violations, forcing a specific language without user opt-in can be a concern when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing instructional content only in Chinese, which can be interpreted as forcing a specific language without user opt-in. The policy for natural-language violations applies to all file types, and there is no indication that the skill offers alternative language support or is explicitly limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire markdown file is written in Chinese and does not provide any indication that users can select another language or that the locale restriction is intentional and justified. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructional content in Chinese and does not indicate that other languages are available or that Chinese is an optional locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all user-facing instructional content in Chinese and does not indicate that the language is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and labels exclusively in Chinese, which can impose a language constraint on users without opt-in. Under the policy rule, forced language choice is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section instructs developers to request fine/coarse location and network permissions but does not explicitly warn that location data is privacy-sensitive, should be minimized, and requires clear user disclosure/consent handling. In a mapping SDK integration skill, that omission can lead downstream users to implement location features without adequate privacy safeguards, increasing the risk of over-collection or non-compliant handling of precise location data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no opt-in, alternative language, or statement that the content is restricted to a Chinese-speaking or China-specific audience. Under the language/locale policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.