Back to skill

Security audit

百度地图地址·汽服门店销售攻店分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed API helper for auto-service store sales analysis and does not show hidden execution, persistence, or unrelated data access.

Install only if you are comfortable sending automotive store queries, pasted map addresses, and coordinates to the DDT/gotoshop-ai.com service. Keep the DDT_API_KEY in your local environment and do not paste it into chats, logs, or repositories.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:33