Back to skill

Security audit

高德地图JSAPI专业版

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a map-development helper, but its activation scope is broader than its stated AMap purpose while requesting read, write, and command execution tools.

Install only if you want this skill to assist with AMap JSAPI map application work. Review when it activates: it should be limited to map integration, routing, traffic, geocoding, visualization, and related AMap tasks, and you should approve file writes or command execution only when they are clearly needed for that work.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
85% confidence
Finding
Overly broad trigger conditions can cause this skill to be invoked for unrelated user requests, granting it access to tools like read, write, and exec in contexts where a narrower skill should have been selected. In an agent environment, poor scoping increases the chance of unintended command execution, file modification, or external API usage under false assumptions about the task.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description includes broad language such as code generation, programming assistance, debugging, testing, and deployment, which can match a wide range of common developer requests beyond AMap-specific tasks. Because the skill also declares powerful tools including exec and write, broad matching raises the risk of inappropriate activation and tool use in unrelated workflows.

Static analysis

No suspicious patterns detected.