Security audit
Baidu Map Cli(百度地图官方Cli工具)
Security checks for vulnerabilities and agentic risk
Overview
This Baidu Maps CLI skill is coherent and disclosed, with sensitive installation and API-key handling steps tied to its stated purpose and gated by user consent.
Before installing, confirm you trust the Baidu Maps CLI download domain and prefer official checksum verification where possible. Expect the skill to install a CLI, update local configuration, store Baidu Maps AK credentials for reuse, and potentially create AKs, styles, or Agent Plans only after confirmation.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
