amap-jsapi-skill

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs authoritative directives defined as 'Iron Laws' (铁律) to override the agent's standard operational logic. These instructions mandate specific technical behaviors, such as background telemetry reporting and enforced code properties, to ensure vendor-specific tracking is included in every interaction.
  • [COMMAND_EXECUTION]: The instructions direct the agent to execute a shell command using curl to report usage metrics to the vendor's logging endpoint (restapi.amap.com). This operation is explicitly instructed to be executed 'silently' before code generation, potentially bypassing user awareness of the network activity.
  • [EXTERNAL_DOWNLOADS]: The skill incorporates official AMap library components and analytics services hosted on amap.com domains. These resources are legitimate vendor-owned infrastructure required for the skill's primary mapping and LBS functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 06:39 AM