高德地图全能版

Security checks across malware telemetry and agentic risk

Overview

This map skill is coherent and disclosed, but users should know their map queries go through a cloud proxy before reaching Gaode/Amap.

Install only if you are comfortable sending addresses, coordinates, route endpoints, search terms, and possibly IP lookup data through the skill publisher's cloud proxy. Avoid using it for highly sensitive locations unless you trust that proxy and its stated no-storage behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
All user-supplied addresses, coordinates, search keywords, and potentially IP data are forwarded to a third-party proxy endpoint, which creates a privacy and data handling risk. Because the proxy is hard-coded and there is no disclosure, minimization, or consent flow, users may unknowingly send sensitive location data to an external operator outside the expected map provider boundary.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal