ClawAudit verdict
bmap-jsapi-three
3D GIS/mapping SDK reference guide for the MapV-Three library that documents API usage patterns for Baidu Maps; reads BMAP_JSAPI_KEY for the mapping service and all described network activity is standard map tile and geocoding requests.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
<script> tag in markdown — potential code injection
reference/initialization.md · code · <script>
Possible hardcoded credential
reference/terrain-tile-provider.md · code · Token: 'your_cesium_access_token
Opens WebSocket connection
reference/twin.md · code · WebSocket
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: BMAP_JSAPI_KEY). Requires 1 system binary.
Is this flag fair?
Thanks — recorded.