Back to skill

Security audit

AMap Map Google Maps Migration

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent map-migration documentation skill, but it includes unsafe copy-ready guidance for sensitive location/device data and mutable install/dependency examples that users should review carefully.

Install only after reviewing the migration examples. Do not send MAC addresses, IMEI, cell tower data, or precise location over plaintext HTTP, and use dedicated restricted API keys instead of shared demo keys for production. Pin CLI, repository, Gradle, and CocoaPods versions in controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
references/web-api-params.md:202
Finding

Transmission of Device Identifiers and Location Data over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/sdk-migration.md:11
Finding

Unpinned Android SDK Dependencies Use Dynamic Versions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:370
Finding

Installation Command Executes an Unpinned Package and Retrieves Mutable Skill Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:41
Finding

Shared API Credentials Are Embedded in Documentation and Generated Examples

Content
View full analysis
**Security Note / 安全说明:** The keys above are **official public promotional keys** provided by AMap for development and testing purposes. They are intentionally embedded to enable zero-friction evaluation. **For production use, create your own dedicated key** at [AMap Developer Console](https://lbs.amap.com/) to ensure quota, security, and traceability. ``` The Web Service key is copied directly into request examples at `SKILL.md:110`, `SKILL.md:124`, `SKILL.md:136`, and `SKILL.md:146`. The JavaScript key is copied into script URLs at `SKILL.md:165` and `SKILL.md:169`. The same values also appear in `references/web-api-params.md` and `references/js-api-detail.md`. ### Technical Analysis The project explicitly identifies these values as public promotional keys rather than private account secrets. Their publication is therefore intentional and is not evidence of theft or unauthorized credential disclosure. Nevertheless, embedding functional shared credentials into copy-ready examples creates insecure credential-management behavior. Shared keys cannot provide reliable per-user attribution, quota isolation, individualized revocation, or production-grade access control. Developers may also copy the examples into deployed applications despite the accompanying production warning. ### Attack Path 1. A third party obtains either key from the publicly distributed Skill documentation. 2. The third party su ...[truncated 820 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly documents a non-HTTPS geolocation endpoint that accepts sensitive device identifiers such as MAC address and IMEI, while only giving a weak note to use HTTPS 'where supported.' If followed, this can expose device identifiers and location-related data to interception or logging in transit, which is especially dangerous because the content is framed as migration guidance developers may copy directly.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/js-api-detail.md (reported line 91)May include surrounding context.

md
title: 'Tokyo',
  icon: 'icon.png'
});
marker.setMap(null); // remove

// AMap
const marker = new AMap.Marker({

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad generic phrases like 'free map API', 'geocoding', 'directions', and 'places search', which can cause the skill to activate in unrelated contexts. Over-broad invocation increases the chance of unintended execution, context hijacking, or surfacing embedded risky guidance such as public keys and insecure endpoints to users who did not request this skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx skills add without pinning an exact package/version, which can fetch whatever the registry serves at execution time. This creates a supply-chain risk: a compromised package, malicious update, or typosquatted dependency could be executed on the user's system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The follow-up statement normalizes npx skills add as an official install path, again without version pinning or integrity guarantees. Recommending an unpinned executable install path increases the chance users will execute unexpected code if the upstream package changes or is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation embeds a concrete AMap API key directly in example script URLs and frames the skill as including free public keys for global developers. Even if intended as a shared or low-privilege key, publishing live credentials in reusable examples encourages insecure key handling, increases the chance of quota theft or abuse, and may lead developers to ship the same exposed key into production.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide encourages use of geocoding, reverse-geocoding, routing, and location SDK features that inherently transmit user-entered addresses, coordinates, and potentially live location data to a third-party provider, but it does not warn developers about privacy, consent, retention, or regional compliance implications. In a migration skill aimed at global developers, omission of this disclosure can lead downstream apps to integrate location flows without proper user notice or legal review, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation includes a live-looking AMap API key directly in a sample request. Even if intended as a public/demo key, publishing concrete credentials in reusable examples encourages unauthorized use, key scraping, quota theft, billing abuse, and downstream developers copying the key into production code. In this skill’s context, the danger is increased because the skill explicitly advertises 'free public API keys included,' suggesting deliberate redistribution of shared credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The geolocation section instructs users to send Wi‑Fi MAC addresses, cell tower data, and device IMEI without any privacy, consent, minimization, or legal-compliance warning. These identifiers can enable device tracking or collection of sensitive location data, and the risk is heightened by the note showing a non-mainland endpoint over HTTP, which could expose telemetry in transit if copied as-is.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file states that no external links are needed because all migration info is contained here, yet the setup and example code require external script URLs to function. This is a mild description-behavior mismatch in the documentation's claim about self-containment rather than a security-sensitive contradiction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.