Scan Report
5 /100
bmap-jsapi-three
使用 MapV-Three 构建专业的 3D 地图和 GIS 应用
Pure documentation skill containing only markdown reference files; no executable code, scripts, or actual credentials. The pre-scan flagged placeholder API key examples in documentation as 'hardcoded credentials', but these are clearly example strings (your_cesium_access_token, your_mapbox_access_token) used in code examples, not real credentials.
Safe to install
No action required. The skill is a documentation reference for MapV-Three 3D mapping library with no executable components.
Findings 1 items
| Severity | Finding | Location |
|---|---|---|
| Info | Placeholder tokens in documentation examples | references/terrain-tile-provider.md:8 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | NONE | NONE | — | No file operations in markdown-only skill |
| Network | NONE | NONE | — | No network code in documentation files |
| Shell | NONE | NONE | — | No scripts or shell commands in this skill |
| Environment | READ | NONE | ✓ Aligned | SKILL.md declares BMAP_JSAPI_KEY requirement but no code accesses it |
4 High 17 findings
High API Key 疑似硬编码凭证
accessToken: 'your_cesium_access_token' references/terrain-tile-provider.md:8 High API Key 疑似硬编码凭证
accessToken = 'your_cesium_access_token' references/terrain-tile-provider.md:29 High API Key 疑似硬编码凭证
accessToken: 'your_access_token' references/terrain-tile-provider.md:91 High API Key 疑似硬编码凭证
accessToken: 'your_mapbox_access_token' references/vector-tile-provider.md:62 Medium External URL 外部 URL
https://your-api-host references/3dtiles-loading.md:249 Medium External URL 外部 URL
https://your-traffic-api references/3dtiles-loading.md:296 Medium External URL 外部 URL
https://api.example.com/points references/datasource/json-datasource.md:129 Medium External URL 外部 URL
https://api.example.com/locations references/datasource/json-datasource.md:169 Medium External URL 外部 URL
https://api.example.com/data references/datasource/json-datasource.md:427 Medium External URL 外部 URL
https://your-terrain-server/terrain-data references/terrain-tile-provider.md:34 Medium External URL 外部 URL
https://terrain-server.example.com/assets/123/v1.0 references/terrain-tile-provider.md:102 Medium External URL 外部 URL
https://your-geoserver:8080/geoserver/wms references/third-party-imagery.md:8 Medium External URL 外部 URL
https://server/wmts/ references/third-party-imagery.md:102 Medium External URL 外部 URL
https://tile-server.example.com/data/ references/third-party-imagery.md:120 Medium External URL 外部 URL
https://server.arcgisonline.com/ArcGIS/rest/services/World_Imagery/MapServer/tile/ references/third-party-imagery.md:126 Medium External URL 外部 URL
https://a.basemaps.cartocdn.com/light_all/ references/third-party-imagery.md:131 Medium External URL 外部 URL
http://local-server:8080 references/vector-tile-provider.md:33 File Tree
47 files · 210.9 KB · 7982 lines Markdown 47f · 7982L
├─
▾
references
│ ├─
▾
common
│ │ ├─
best-practices.md
Markdown
│ │ ├─
coordinate-system.md
Markdown
│ │ ├─
event-binding.md
Markdown
│ │ └─
faq.md
Markdown
│ ├─
▾
datasource
│ │ ├─
csv-datasource.md
Markdown
│ │ ├─
dataitem.md
Markdown
│ │ ├─
geojson-datasource.md
Markdown
│ │ └─
json-datasource.md
Markdown
│ ├─
3dtiles-loading.md
Markdown
│ ├─
circle.md
Markdown
│ ├─
cluster.md
Markdown
│ ├─
datasource.md
Markdown
│ ├─
dom-overlay.md
Markdown
│ ├─
easing-function.md
Markdown
│ ├─
editor.md
Markdown
│ ├─
effect-point.md
Markdown
│ ├─
engine.md
Markdown
│ ├─
heatmap.md
Markdown
│ ├─
imagery-tile-provider.md
Markdown
│ ├─
initialization.md
Markdown
│ ├─
label.md
Markdown
│ ├─
marker-types.md
Markdown
│ ├─
marker.md
Markdown
│ ├─
materials.md
Markdown
│ ├─
measure.md
Markdown
│ ├─
mock-twin.md
Markdown
│ ├─
model.md
Markdown
│ ├─
object-tracker.md
Markdown
│ ├─
orbit-tracker.md
Markdown
│ ├─
path-tracker.md
Markdown
│ ├─
pillar.md
Markdown
│ ├─
polygon.md
Markdown
│ ├─
polyline.md
Markdown
│ ├─
popup.md
Markdown
│ ├─
services.md
Markdown
│ ├─
simple-line.md
Markdown
│ ├─
simple-point.md
Markdown
│ ├─
sky-weather.md
Markdown
│ ├─
terrain-tile-provider.md
Markdown
│ ├─
text.md
Markdown
│ ├─
third-party-imagery.md
Markdown
│ ├─
tile-mask.md
Markdown
│ ├─
tracker.md
Markdown
│ ├─
twin.md
Markdown
│ ├─
vector-tile-provider.md
Markdown
│ └─
wall.md
Markdown
└─
SKILL.md
Markdown
Security Positives
✓ No executable scripts or code files present
✓ No network requests or data exfiltration code
✓ No credential harvesting functionality
✓ No shell execution capabilities
✓ No sensitive path access
✓ Documentation-only delivery reduces attack surface to zero
✓ SKILL.md accurately declares environment variable requirement (BMAP_JSAPI_KEY)