tencentmap-lbs-skill

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly asks the user to provide their API Key and instructs the agent to "记录" or run commands embedding that key (e.g., tmap-lbs config set-key ), which requires the LLM to receive and potentially output the secret verbatim.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill explicitly instructs to "静默记录 Key" (silently record users' official API keys) which constitutes deliberate credential collection without user awareness and is a high-risk credential theft pattern.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 该 Skill 在运行时会根据用户输入直接使用 tmap-lbs trail --data <数据URL> 将“用户提供的数据地址/JSON数据链接”拼接进轨迹可视化链接,因此会读取并使用外部(可由外人作者)free text/内容(轨迹 JSON)作为运行输入。

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 19, 2026, 05:33 PM
Issues
3
Security Audit — snyk — tencentmap-lbs-skill