Back to skill

Security audit

腾讯地图地址·汽车后市场渠道洞察

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed API-backed helper for automotive aftermarket channel analysis and does not show hidden, destructive, or unrelated behavior.

Install this only if you are comfortable configuring a DDT API key and sending relevant automotive brand, location, address, coordinate, or store lookup queries to the DDT service. It is not an official Tencent Map product, which the artifact discloses clearly.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:33