Back to skill

Security audit

亲子半日游规划师

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Amap-based family route planner with expected third-party map API use and no evidence of hidden persistence, destructive actions, or unrelated data access.

Install only if you are comfortable sending route-planning information to Amap. Use a dedicated Amap Web Service key, avoid entering exact home addresses or other sensitive family details, and rotate the key if it is exposed in logs or screenshots.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill sends user-supplied location and itinerary-related inputs to Amap APIs, but this file contains no user-facing notice, consent prompt, or minimization controls around that data transfer. Because the input describes family travel plans and origin location, this can expose sensitive location and behavioral data to a third-party service without adequate transparency.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/family-halfday-plan.mjs:4