Back to skill

Security audit

Travel Mapify

Security checks across malware telemetry and agentic risk

Overview

Travel Mapify’s map-making purpose is coherent, but an included local Amap proxy exposes unsanitized web request inputs to shell command execution.

Only install or run this skill if you trust the publisher and are comfortable with local servers. Do not run the included Amap proxy until its shell command construction is fixed, and prefer a version that validates inputs, avoids shell execution, restricts CORS, and clearly declares its required external dependencies.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/amap-proxy.js:25