Back to skill

Security audit

腾讯地图api调用技能

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tencent Maps command-line integration, with some documentation and input-handling weaknesses but no hidden, destructive, or unrelated behavior.

Before installing, use a restricted Tencent Maps API key with quotas and billing alerts, avoid submitting sensitive home/work/customer locations unless appropriate, and be aware that all map queries go to Tencent. The publisher should add explicit privacy notices, URL-encode parameters, validate coordinates and numeric fields, and either implement or remove the advertised route feature.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tencent_map.sh:41
Finding

API Credential Exposure and Query-Parameter Injection Through URL Construction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

整体上,代码的主要用途与声明高度一致,都是腾讯地图 API 集成,且实现了地点搜索、逆地理编码、地理编码和周边搜索,没有发现与地图功能无关的越权或隐藏行为。不过存在一个明显的描述-行为不一致:声明提到“路线规划”等功能,代码中的提示信息也列出了 route,但实际并没有对应的 route case 分支,调用 route 会落入默认错误分支。因此应判定为存在描述与实际能力不完全匹配。

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/tencent_map.sh (reported line 44)May include surrounding context.

sh
URL="${BASE_URL}/place/v1/search?boundary=region(${REGION},0)&keyword=${KEYWORD}&page_index=${PAGE_INDEX}&page_size=${PAGE_SIZE}&key=${API_KEY}&output=json"
        
        # 发送请求
        RESPONSE=$(curl -s "$URL")
        
        # 解析并格式化结果
        echo "$RESPONSE" | python3 -c "

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/tencent_map.sh (reported line 88)May include surrounding context.

sh
URL="${BASE_URL}/geocoder/v1/?location=${LAT},${LNG}&key=${API_KEY}&output=json"
        
        RESPONSE=$(curl -s "$URL")
        
        echo "$RESPONSE" | python3 -c "
import sys

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/tencent_map.sh (reported line 120)May include surrounding context.

sh
URL="${BASE_URL}/geocoder/v1/?location=${LAT},${LNG}&key=${API_KEY}&output=json"
        
        RESPONSE=$(curl -s "$URL")
        
        echo "$RESPONSE" | python3 -c "
import sys

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/tencent_map.sh (reported line 153)May include surrounding context.

sh
URL="${BASE_URL}/geocoder/v1/?location=${LAT},${LNG}&key=${API_KEY}&output=json"
        
        RESPONSE=$(curl -s "$URL")
        
        echo "$RESPONSE" | python3 -c "
import sys

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes location-search features but does not disclose that user-supplied addresses, keywords, and coordinates are transmitted to Tencent's third-party Web Service API. This omission can mislead operators and end users about data flows, creating privacy and compliance risk when sensitive location data is processed without clear notice or consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents and invokes shell execution but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization and review gap: operators may approve or run the skill without clear visibility that it requires shell access and outbound network-capable commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill encourages users to submit addresses, coordinates, and search terms to an external Tencent API without clearly warning that this data leaves the local environment. This can cause unintended disclosure of sensitive location information, especially when users input home, workplace, customer, or travel data under the assumption the processing is local.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are generic map-related terms that can match many normal user requests, causing this skill to activate more often than intended. Because the skill has network access and uses an API key, over-broad triggering increases the chance of unintended data transmission, unnecessary external API calls, and invocation hijacking over more appropriate skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code constructs a URL containing user query data and the Tencent Maps API key, then transmits it via curl to an external network endpoint. Although network access is central to the script's purpose, there is no visible disclosure in the script output or prompts that user-provided address/location data will be sent to Tencent's API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The reverse_geocode branch sends precise location coordinates to Tencent Maps using curl. Exact coordinates can be sensitive location data, and the script does not display any warning, confirmation, or privacy notice before sending them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This branch transmits the supplied address string to Tencent Maps over the network. Address data may be sensitive, but the script provides no user-facing disclosure that the input will be shared with a third-party mapping provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The around branch transmits latitude, longitude, radius, and keyword data to Tencent Maps. Because this includes precise location information and search intent, the script should disclose the external transmission to the user but currently does not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

A language or locale policy issue exists when a skill effectively forces a specific language without user opt-in or justification. This file presents all usage guidance only in Chinese and does not mention any optional language support or region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file includes a batch script that exports an API key and writes collected POI data to a local JSON file, but the surrounding documentation does not warn users that the script stores retrieved data locally or that they should protect the credential. For markdown files, missing disclosures about behaviors affecting user data or privacy should be flagged when omitted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script's comments and especially its runtime error/help messages are presented only in Chinese, which effectively forces a single language for users. The file does not indicate that the skill is intentionally limited to Chinese-speaking users or provide any opt-in language selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.