Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/amap.js help
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Amap command-line skill that sends user-requested map, route, weather, POI, and IP-location queries to Amap using an AMAP_KEY.
Install only if you are comfortable sending the places, coordinates, routes, POI lookups, weather cities, IP addresses, and your Amap API key to Amap's remote service. Avoid submitting sensitive home, workplace, or travel-pattern data unless that disclosure is intended.
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
Referenced artifact was not completely inspected
node scripts/amap.js help
The skill declares capabilities that require environment-variable access and outbound network access, but it does not define an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it easier for the skill to access sensitive runtime resources without clear user or platform visibility.
The documentation describes commands that transmit user-supplied addresses, coordinates, routes, weather queries, and IP addresses to Amap services, but it does not warn users that this data leaves the local environment. That omission can cause unintentional disclosure of sensitive location or network-identifying information, especially for home addresses, travel patterns, or public IPs.
The CLI forwards user-supplied addresses, coordinates, and IP addresses to a remote Amap MCP endpoint, which can expose sensitive location-related data without an explicit privacy notice or consent step. While expected for a mapping tool, this still creates a real privacy risk because users may not realize their precise location data is being transmitted to a third party.
The documented usage consistently uses Chinese cities, addresses, POI names, and labels, which implies a locale-specific interaction model. Because the file does not clearly state that the skill is China-specific or offer user opt-in for that locale expectation, it risks violating the language/locale policy.
The description string is entirely in Chinese ("高德地图 Skill 命令行工具") and the file does not indicate that the skill is region-specific or that users can choose another language. This creates a natural-language locale constraint that may violate organizational language-choice policy if the skill is intended for broader use.
No suspicious patterns detected.