Back to skill

Security audit

高德地图全能版

Security checks for vulnerabilities and agentic risk

Overview

This map skill matches its stated purpose and shows no hidden persistence or destructive behavior, but location and route queries are sent to a remote proxy.

Install only if you are comfortable sending map queries, addresses, coordinates, route endpoints, weather cities, and optional IP-location lookups to the skill's remote proxy and downstream map API. Avoid using it for highly sensitive home, work, medical, or private travel locations unless you trust the proxy operator. Only set PROXY_TOKEN to a token intended for this proxy service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tainted flow: 'req' from os.environ.get (line 18, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · main.py (reported line 25)May include surrounding context.

python
)
    _timeout = timeout or TIMEOUT
    try:
        with urllib.request.urlopen(req, timeout=_timeout) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Tainted flow: 'req' from os.environ.get (line 18, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/main.py (reported line 25)May include surrounding context.

python
)
    _timeout = timeout or TIMEOUT
    try:
        with urllib.request.urlopen(req, timeout=_timeout) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        err = ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises network-backed capabilities and likely relies on external access, but it does not declare any explicit tool scope or permissions boundaries. This weakens least-privilege controls and makes it harder for reviewers and users to understand what external access the skill requires, increasing the risk of unintended data exposure or overly broad runtime access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promotes IP-based location lookup, including current-IP inference when no IP is provided, but does not present a clear, prominent privacy warning or consent flow. IP-derived location can reveal a user's approximate whereabouts and may be sent to a third-party proxy/service without the user fully understanding that location inference is occurring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level natural-language description is presented only in Chinese and does not indicate any language choice or opt-in. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill sends potentially sensitive user-provided addresses, coordinates, route endpoints, and IP-related data to a third-party proxy service rather than directly to the map provider. Because the proxy is external and opaque, users are not informed that their location/travel data is being transmitted and potentially retained by an intermediary, creating a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level natural-language description is entirely in Chinese and presents the skill as a Chinese-only experience without any opt-in or alternative language handling. Under the policy, forcing a specific language without user choice is a locale/language policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · main.py (reported line 15)May include surrounding context.

python
TIMEOUT = 30


def _call_proxy(rtype, params, timeout=None):
    """调用高德代理API"""
    body = json.dumps({"type": rtype, "params": params}, ensure_ascii=False, separators=(",", ":")).encode("utf-8")
    req = urllib.request.Request(

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/main.py (reported line 15)May include surrounding context.

python
TIMEOUT = 30


def _call_proxy(rtype, params, timeout=None):
    """调用高德代理API"""
    body = json.dumps({"type": rtype, "params": params}, ensure_ascii=False, separators=(",", ":")).encode("utf-8")
    req = urllib.request.Request(

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill sends user-supplied addresses, POI queries, routes, weather locations, and possibly IP data to a third-party proxy endpoint rather than directly to a first-party map provider. In the context of a mapping skill, that data can reveal highly sensitive travel patterns and location history, and the code provides no notice, consent, or minimization before transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing descriptions, examples, and instructions are presented exclusively in Chinese, with no indication that users may choose another language. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill reads PROXY_TOKEN from the environment and uses it in outbound requests, but there is no user-facing disclosure, warning comment, or documentation in this file explaining that environment-based credentials are consumed. This matches the code-file criterion for sensitive environment variable access lacking any form of warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script reads a proxy token from the environment and uses it in outbound request headers, but there is no user-facing notice that the skill depends on and transmits a credential to a remote service. The existing code comments/docstrings are implementation-focused rather than a disclosure of credential handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.