bmap-jsapi-three

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation and instructional code snippets for the MapV-Three library. It does not contain any executable scripts, executables, or background processes that perform unauthorized actions.- [CREDENTIALS_UNSAFE]: The documentation correctly handles API key requirements. It identifies the 'BMAP_JSAPI_KEY' as an environment variable in the skill metadata and consistently uses clear placeholders such as '您的AK密钥' or 'your_baidu_ak' in example code to prevent the inclusion of real secrets.- [EXTERNAL_DOWNLOADS]: The skill facilitates the loading of geospatial data and map tiles from various well-known and reputable services, including Baidu Maps, Tianditu, Microsoft Bing, Mapbox, and Cesium. These external references are standard for GIS applications and target established technology providers.- [DATA_EXFILTRATION]: While the skill provides tools for fetching data from remote URLs (e.g., GeoJSON, CSV, or 3D Tiles), these operations are transparently documented as core functionality for mapping and visualization, with no evidence of sensitive local data being sent to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 05:51 AM