baidu map jsapi-ui-kit
v1.0.3百度地图 JavaScript API ui-kit 组件库开发指南。提供地点自动补全(PlaceAutocomplete)、地点检索(PlaceSearch)、地点详情(PlaceDetail)和路径规划(RoutePlan)组件的使用参考。当用户需要:(1) 实现地点搜索输入框自动补全、(2) 在百度地图上实...
⭐ 0· 435·1 current·1 all-time
bybaidu-map@wahddbing
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
The skill is documentation for @baidumap/jsapi-ui-kit and the declared requirements (node for npm examples and BMAP_JSAPI_KEY for Baidu JS API calls) align with that purpose. However the skill metadata lacks a homepage or authoritative source; absence of a source repository or homepage reduces ability to verify authenticity.
Instruction Scope
SKILL.md and referenced docs contain usage examples and API explanations only. Instructions reference loading the Baidu Maps JS API and CDN/unpkg URLs for the UI kit — which is expected. There are no instructions to read unrelated local files, exfiltrate data, or contact unexpected endpoints.
Install Mechanism
There is no install spec and no code files; the skill is instruction-only. Risk from installation is low because nothing is downloaded or written by the skill itself.
Credentials
Only one environment variable is required (BMAP_JSAPI_KEY) and it is the primary credential necessary to use Baidu's JS API. Requiring 'node' is reasonable given npm install examples. No unrelated secrets or config paths are requested.
Persistence & Privilege
The skill does not request permanent presence (always is false) and does not modify other skills or agent-wide settings. Autonomous invocation is allowed by default but not combined with other high-risk factors here.
Scan Findings in Context
[no_code_files_to_scan] expected: The static scanner had no code files to analyze because this is an instruction-only skill containing documentation and markdown files; absence of findings is therefore expected but does not guarantee authenticity.
Assessment
This skill appears coherent: it provides documentation and examples for the Baidu Maps jsapi UI kit and only asks for a single Baidu API key and node (for npm examples). Before installing or using it: 1) confirm the skill's origin (official npm package or trusted author) since homepage/source are missing; 2) use a Baidu API key with minimal required permissions and, if possible, a separate key for development/testing; 3) when copying examples into production, verify CDN/package integrity (check npm package name and publisher, or use an official CDN); 4) never paste other unrelated secrets into prompts that use this skill. If you can supply the official package repository or homepage, that would raise confidence to high.Like a lobster shell, security has layers — review code before you run it.
latestvk976qm4qwf1cf9h7r9fzxw708x83ze5c
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
Binsnode
EnvBMAP_JSAPI_KEY
Primary envBMAP_JSAPI_KEY
