tencentmap-lbs-skill
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly asks the user to provide their API Key and instructs the agent to "记录" or run commands embedding that key (e.g., tmap-lbs config set-key ), which requires the LLM to receive and potentially output the secret verbatim.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill explicitly instructs to "静默记录 Key" (silently record users' official API keys) which constitutes deliberate credential collection without user awareness and is a high-risk credential theft pattern.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该 Skill 在运行时会根据用户输入直接使用
tmap-lbs trail --data <数据URL>将“用户提供的数据地址/JSON数据链接”拼接进轨迹可视化链接,因此会读取并使用外部(可由外人作者)free text/内容(轨迹 JSON)作为运行输入。
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata