Back to skill

Security audit

Baidu Map Cli(百度地图官方Cli工具)

Security checks for vulnerabilities and agentic risk

Overview

This Baidu Maps CLI skill is coherent and disclosed, with sensitive installation and API-key handling steps tied to its stated purpose and gated by user consent.

Before installing, confirm you trust the Baidu Maps CLI download domain and prefer official checksum verification where possible. Expect the skill to install a CLI, update local configuration, store Baidu Maps AK credentials for reuse, and potentially create AKs, styles, or Agent Plans only after confirmation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.