Back to skill

Security audit

高德地图JSAPI免费版

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a map-development helper, but it asks for broad agent powers and describes generic automation beyond that purpose.

Review this before installing. It is not evidence of malware, but you should only use it for AMap JSAPI work, keep it scoped to the relevant project files, and approve any shell command or API-key handling explicitly.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
The skill is presented in the manifest as a narrowly scoped AMap JSAPI helper, but the body later expands into broad automation capabilities including file handling, API integration, browser use, and command execution. That scope drift is dangerous because it can cause an agent or operator to grant powerful tools under a misleading description, increasing the chance of unintended command execution or data access outside the expected map-development use case.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Advertising exec capability for a map JSAPI helper is unnecessary and expands the attack surface beyond what the stated task requires. Even without an explicit payload, normalizing shell access in a low-risk integration skill can lead agents to run local commands, network diagnostics, or generated scripts based on untrusted input.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill claims generic file processing and information retrieval capabilities unrelated to AMap JSAPI development, indicating unjustified privilege expansion. In an agent setting, this can encourage reading, writing, or searching arbitrary local/project data under the cover of a benign map-development task.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger condition is overly broad, saying to use the skill for API integration, interface docking, webhook configuration, and system connections generally, which far exceeds the stated map-helper scope. Broad invocation criteria increase the likelihood that the agent selects this skill in unrelated contexts where its extra tools and generic automation claims can be misapplied.

Static analysis

No suspicious patterns detected.