Back to skill

Security audit

运营商5G基站位置查询(AI付版) - 聚合数据

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed paid cell-tower location lookup that sends user-provided tower identifiers to a named third-party API and uses Alipay payment flow.

Install only if you are comfortable sending the entered cell-tower identifiers to Juhe's API and paying through the Alipay flow. Use it only for locations you are authorized to check, confirm the parameters and payment details before proceeding, and avoid using it to locate another person without consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill handles privacy-sensitive telecom identifiers and returns precise location data from a third-party paid API, but the description and workflow do not clearly warn users that submitting MCC/MNC/LAC/CI may reveal device-related location information to an external provider. In a location lookup and payment context, lack of explicit privacy notice and consent language increases the risk of unintended disclosure, misuse for tracking, and user surprise about what data is shared and what precision is returned.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.