skills/bighardperson/computer-science-skills-collection/tencentmap-jsapi-gl-skill/Gen Agent Trust Hub
tencentmap-jsapi-gl-skill
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses directive language to override the agent's default behavior, establishing a mandatory sequence that requires an API key check before any other processing can occur. Evidence in SKILL.md: '本 Skill 加载后,第一个动作必须是检查是否存在正式 Key... 停止等待用户选择,不得在用户选择之前进行任何分析、读取文件、规划方案或编写代码的操作' and '⛔ 强制拦截(最高优先级)'.
- [CREDENTIALS_UNSAFE]: Multiple demo HTML files and documentation snippets include a hardcoded public demo API key used for accessing Tencent position services. Evidence: The key 'OB4BZ-D4W3U-B7VVO-4PJWW-6TKDJ-WPB77' is present in numerous files within the 'references/jsapigl/demos/' and 'references/visualization/demos/' directories, as well as within code samples in the documentation files.
Audit Metadata