百度地图 CLI 助手

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill downloads and executes a binary from a Baidu Cloud bucket (bj.bcebos.com) and modifies the user's shell configuration (~/.zshenv) for persistence. It includes a high-risk 'highest priority' instruction in SKILL.md that forces the agent to automatically execute update commands found in any command output, which could be exploited to run arbitrary code. Furthermore, it mandates the creation of Baidu Maps API keys with unrestricted referrers ('*'), which is a security vulnerability that exposes the user's credentials to unauthorized use.