tencentmap-lbs-skill

Fail

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes 'Forceful Behavior' (强制行为) instructions that override the agent's core operational logic. It mandates that the agent must stop all analysis, file reading, and code generation immediately upon loading until a specific API key condition is met, bypassing the agent's standard autonomous reasoning and processing pipeline.
  • [REMOTE_CODE_EXECUTION]: The skill requires the global installation and execution of the @tencent-map/lbs-skills NPM package. Although the package name suggests official Tencent provenance, the skill is authored by hk-hub. This discrepancy indicates potential brand impersonation intended to facilitate the execution of untrusted third-party code on the host system.
  • [DYNAMIC_EXECUTION]: Instructions explicitly guide the agent to perform dynamic remote script execution via JSONP. It provides a code snippet to create and inject <script> tags that fetch and execute JavaScript from h5gw.map.qq.com. This pattern allows for the execution of arbitrary remote code within the execution context.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect injection by ingesting untrusted data (location names, search keywords,景点, and data URLs) and interpolating it directly into shell command arguments (e.g., tmap-lbs nearby --location {location}).
  • Ingestion points: User-provided locations, keywords, and URLs in SKILL.md and references/.
  • Boundary markers: None identified.
  • Capability inventory: Shell command execution via tmap-lbs CLI tools across all scenarios.
  • Sanitization: No instructions for escaping shell metacharacters or validating input strings are provided.
  • [COMMAND_EXECUTION]: The skill relies on multiple shell commands (tmap-lbs search, tmap-lbs route, tmap-lbs travel, tmap-lbs trail) which take user-controlled parameters. The lack of input validation or structured parameter handling creates a high risk of arbitrary command execution if a user provides shell metacharacters as part of a location or keyword.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — tencentmap-lbs-skill