Back to skill

Security audit

百度地图地址·汽车后市场渠道洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped API guide for automotive channel analysis and does not contain executable code or hidden persistence.

Before installing, confirm you are comfortable using a third-party DDT/Open API key and sending relevant brand, address, coordinate, or store lookup queries to the configured service. Do not paste real API keys into chat or commit them to files, and note that the skill explicitly is not an official Baidu Map product.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:33