Back to skill

Security audit

腾讯地图地址·餐饮连锁拓店选址分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped restaurant site-selection helper that uses a disclosed external API and does not show hidden installation, persistence, or local data access behavior.

Install only if you are comfortable sending restaurant brand and address/candidate-site queries to the GotShop/DDT API using your own API key. The artifact does not request broad local access or hidden authority, but the provider will receive the business queries needed for analysis.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.