Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:61
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a purpose-aligned Gaode/Amap map skill, but it needs your Amap API key and sends selected searches, coordinates, and visualization data to Amap services.
Before installing, make sure you are comfortable giving this skill access to an Amap Web Service key and sending your requested searches, route endpoints, coordinates, and heatmap data URLs to Amap. Prefer a restricted API key, avoid private or tokenized heatmap data URLs, and only use the local Electron socket helper with a trusted companion app.
67/67 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access