Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/amap-proxy.js:25
Security audit
Security checks across malware telemetry and agentic risk
Travel Mapify’s map-making purpose is coherent, but an included local Amap proxy exposes unsanitized web request inputs to shell command execution.
Only install or run this skill if you trust the publisher and are comfortable with local servers. Do not run the included Amap proxy until its shell command construction is fixed, and prefer a version that validates inputs, avoids shell execution, restricts CORS, and clearly declares its required external dependencies.
67/67 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec