高德打车

Security checks across malware telemetry and agentic risk

Overview

This map and taxi helper sends location queries through a disclosed cloud proxy to provide Gaode map features, with no evidence of local persistence or unrelated behavior.

Install only if you are comfortable sending map searches, addresses, coordinates, IP-location queries, and taxi route details to the skill publisher’s cloud proxy for Gaode lookups. Avoid entering sensitive home, workplace, or private itinerary details unless you trust the proxy operator’s no-storage claim.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill sends sensitive user-provided addresses, coordinates, and possibly IP-related data to a third-party proxy endpoint instead of directly to the expected map provider, without clear disclosure or consent. This creates a privacy and data-handling risk because the proxy can log, inspect, retain, or misuse precise location data and trip intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal