Back to skill

Security audit

tmap-jsapi-gl-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tencent Maps development skill, but it bundles a concrete API key in many examples and some demos transmit location data without clear notice.

Install only if you are comfortable using a Tencent Maps development reference that includes many runnable demos. Do not reuse the bundled API key; create and restrict your own Tencent Maps key, keep it in TMAP_JSAPI_KEY, and replace concrete keys before copying code. When opening demos, assume map queries, addresses, coordinates, IP-derived location, and browser requests may be sent to Tencent or loaded third-party scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/jsapigl/demos/个性化地图_切换地图个性化样式.html:10
Finding

Hardcoded Tencent Maps API Key in Bundled Documentation and Executable Demos

Content
View full analysis
``` Other confirmed usage patterns include direct inclusion in service requests: ```javascript url += "&key=OB4BZ-D4W3U-B7VVO-4PJWW-6TKDJ-WPB77"; // Development key ``` ```javascript url: "https://apis.map.qq.com/ws/district/v1/getchildren?key=OB4BZ-D4W3U-B7VVO-4PJWW-6TKDJ-WPB77&output=jsonp&get_polygon=2&max_offset=3000" ``` ### Technical Analysis A Tencent Maps API key is embedded directly in executable HTML examples and documentation. This conflicts with the Skill configuration in `SKILL.md`, which declares `TMAP_JSAPI_KEY` as the required environment variable and recommends using `{TMAP_JSAPI_KEY}` in generated code. Although browser-facing map keys are necessarily transmitted to clients, they should still be restricted to authorized domains, APIs, and quotas. Committing a concrete reusable key to the package makes it immediately discoverable and encourages users or Agents to copy it into generated applications. The key is also placed directly in web-service request URLs in some examples. The audit did not verify whether the key rem ...[truncated 1723 chars]
Remediation
View remediation
``` 3. **Enforce server-side key restrictions** - Restrict browser keys to explicitly authorized referrer domains. - Enable only the Tencent Maps APIs required by the application. - Apply suitable request quotas and billing alerts. - Use separate keys for development, demonstration, testing, and production. 4. **Prevent generated-code propagation** - Amend the Skill instructions to explicitly prohibit copying credentials from reference demos. - Require generated examples to use placeholders or configuration injection. - Clearly state that users must create and restrict their own Tencent Maps key. 5. **Add automated secret detection** - Run secret scanning in pre-commit hooks and continuous integration. - Include patterns for Tencent Maps key formats and credentials embedded in URL query strings. - Fail builds when concrete API keys are found in documentation, source code, or demo assets. 6. **Verify remediation comprehensively** - Search the entire repository for the exposed key after replacement. - Confirm that no historical build artifacts or packaged releases still contain it. - Rotate the credential even after removal because repository deletion does not invalidate previously distributed copies ...[truncated 7 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (359)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 464)May include surrounding context.

md
<br><br>
## MVTLayer{#MVTLayer}
-------
​&nbsp;&nbsp;&nbsp;&nbsp;用于创建符合mapbox-vector-tile标准的图层对象,叠加在地图上进行显示;**注意,添加MVTLayer后不支持地图设置中心点偏移**。


| 构造函数                                            |

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/jsapigl/docs/附加库:矢量数据图层.md (reported line 38)May include surrounding context.

md
<br><br>
## MVTLayer{#MVTLayer}
-------
​&nbsp;&nbsp;&nbsp;&nbsp;用于创建符合mapbox-vector-tile标准的图层对象,叠加在地图上进行显示;**注意,添加MVTLayer后不支持地图设置中心点偏移**。


| 构造函数                                            |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it should auto-trigger whenever users mention 腾讯地图、jsapi、jsapi-gl or related map-development needs, which is broad enough to activate in loosely related conversations. Over-broad triggering can cause inappropriate context injection, unnecessary access to privileged skill resources, and user confusion when the assistant applies this skill outside its intended scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill content is entirely Chinese and presents all instructions, examples, and workflow in a single language without indicating that output language should follow user preference. This can override or bias the assistant's response language unexpectedly, reducing usability and potentially causing misunderstanding in multilingual or English-language sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The page automatically calls locate() on load, which triggers an IP-based geolocation request to a remote Tencent Maps service without any explicit user notice or consent flow. Even though this is a demo, it processes potentially privacy-sensitive network-derived location data and displays it immediately, which can violate privacy expectations and create compliance issues in real applications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The page sends user-typed keywords and map context such as the current center or bounds to Tencent Map backend services for suggestions and search, but it does not clearly inform users that their input and location context will be transmitted off-page. This is a real privacy/security issue because users may enter sensitive places, addresses, or other personal queries without meaningful notice or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The convert function takes the user-entered address and submits it via TMap.service.Geocoder.getLocation, which transmits potentially sensitive location data to a third-party service. In this code, there is no confirmation prompt, privacy notice, or explanatory comment near the operation to disclose that the address will be sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This HTML/JavaScript file performs a network request to Tencent's geocoding service using user-provided latitude/longitude, then displays the returned address. There is no visible warning near the input/button or other disclosure that the entered location data will be transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This HTML/JavaScript file loads multiple third-party remote scripts and later performs an API request to Tencent map services, but the file contains no user-facing notice, comment, or visible disclosure explaining that network requests to external services will occur. Because this is a code file and the behavior transmits browser/system context to external endpoints, it matches the missing-warning criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code uses JSONP to fetch remote data, which executes returned content as script rather than parsing it as inert JSON. If the upstream endpoint is compromised, misconfigured, or intercepted in a broader threat scenario, this can lead to arbitrary script execution in the page context; in a map demo skill, that is more dangerous than normal data fetching because the browser trusts the response as code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that when enableCustom is true, the content field accepts a DOM/HTML string for the info window, but it provides no warning about sanitizing untrusted input. If developers pass user-controlled content into this API, it can lead to DOM-based XSS in applications that render attacker-supplied HTML inside the map info window.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/地图.md (reported line 246)May include surrounding context.

md
|              名称              |    类型   |                             说明                             |
| :-| :- | :- |
|     <br>preserveDrawingBuffer    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  |    <br>Boolean &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  | 保留地图的渲染缓冲,在一些结合开源库需要导出图片的场景下(如 dom-to-image html2canvas),需要设置这个参数为true;默认为false,查看示例
| enableBloom | Boolean | 是否启用泛光效果(请确认浏览器支持WebGL2) |
| fogOptions |fogOptions | 边际雾化设置 |
| skyOptions |SkyOptions | 天空背景设置 |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 273)May include surrounding context.

md
|              名称              |    类型   |                             说明                             |
| :-| :- | :- |
|     <br>preserveDrawingBuffer    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  |    <br>Boolean &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  | 保留地图的渲染缓冲,在一些结合开源库需要导出图片的场景下(如 dom-to-image html2canvas),需要设置这个参数为true;默认为false,查看示例
| enableBloom | Boolean | 是否启用泛光效果(请确认浏览器支持WebGL2) |
| fogOptions |fogOptions | 边际雾化设置 |
| skyOptions |SkyOptions | 天空背景设置 |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 280)May include surrounding context.

md
|              名称              |    类型   |                             说明                             |
| :-| :- | :- |
|     <br>preserveDrawingBuffer    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  |    <br>Boolean &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  | 保留地图的渲染缓冲,在一些结合开源库需要导出图片的场景下(如 dom-to-image html2canvas),需要设置这个参数为true;默认为false,查看示例
| enableBloom | Boolean | 是否启用泛光效果(请确认浏览器支持WebGL2) |
| fogOptions |fogOptions | 边际雾化设置 |
| skyOptions |SkyOptions | 天空背景设置 |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 494)May include surrounding context.

md
|              名称              |    类型   |                             说明                             |
| :-| :- | :- |
|     <br>preserveDrawingBuffer    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  |    <br>Boolean &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  | 保留地图的渲染缓冲,在一些结合开源库需要导出图片的场景下(如 dom-to-image html2canvas),需要设置这个参数为true;默认为false,查看示例
| enableBloom | Boolean | 是否启用泛光效果(请确认浏览器支持WebGL2) |
| fogOptions |fogOptions | 边际雾化设置 |
| skyOptions |SkyOptions | 天空背景设置 |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/文本标记.md (reported line 35)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。 查看示例

|事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;		|参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;	&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;			|说明|
| :- | :- | :- |
|click	|GeometryOverlayEvent	|点击事件|
|dblclick	|GeometryOverlayEvent|双击事件|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/点标记.md (reported line 36)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 37)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 160)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/矢量图形.md (reported line 390)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/自定义图层.md (reported line 104)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/自定义图层.md (reported line 131)May include surrounding context.

md
**事件:**</br>
&nbsp;&nbsp;&nbsp;&nbsp;监听事件通过on、off方法绑定与解绑。查看示例

| 事件名&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;| 参数&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; | 说明 |
| :- | :- |:- |
|click	|GeometryOverlayEvent	|点击事件。|
|dblclick	|GeometryOverlayEvent	|双击事件。|

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all user-facing guidance in a single enforced language, which can violate language/locale policy when no opt-in or alternative is provided. The content does not state that the skill is region-specific or otherwise justified to require Chinese only.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/自定义图层.md (reported line 75)May include surrounding context.

md
&nbsp;&nbsp;&nbsp;&nbsp;WMSLayer配置参数。

| 名称  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;    | 类型  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;    | 说明                                                         |
| :---------- | :-------- | :----------------------------------------------------------- |
| url         | String    | 地图服务地址                                                 |
| map         | Map       | 展示图层的地图对象                                           |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/jsapigl/docs/自定义图层.md (reported line 75)May include surrounding context.

md
&nbsp;&nbsp;&nbsp;&nbsp;WMSLayer配置参数。

| 名称  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;    | 类型  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;    | 说明                                                         |
| :---------- | :-------- | :----------------------------------------------------------- |
| url         | String    | 地图服务地址                                                 |
| map         | Map       | 展示图层的地图对象                                           |

Static analysis

No suspicious patterns detected.