amap-jsapi-skill
AMap JSAPI Web マップを構築
AMap JSAPI のセットアップには、ライフサイクル、キー、プラグインに関する多くの詳細があり、Web マップ作業の妨げになることがあります。このスキルは、安全なマップ初期化、オーバーレイ、レイヤー、ルーティング、検索、イベントに関する重点的なリファレンスと例を提供します。
このスキルはパックに含まれています
タスクに必要なすべてのスキルを、パックごと 1 コマンドでインストールできます。
インストール前に停止して確認を求めてください。
計画を確認し、ファイルを変更する前にユーザーの明示的な同意を得てください。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "amap-jsapi-skill" from https://skillstore.io/skills/amap-web-amap-jsapi-skill.md and its manifest at https://skillstore.io/api/skills/amap-web-amap-jsapi-skill/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「amap-jsapi-skill」を使用しています。 北京のオフィス所在地向けに基本的な AMap JSAPI ページを作成してください。
期待される結果:
- ローダー、キープレースホルダー、セキュリティ設定、マップコンテナに関する簡潔なセットアップ計画。
- 中心座標、3D ビュー設定、スケールコントロール、クリーンアップガイダンスを含むマップ初期化の概要。
「amap-jsapi-skill」を使用しています。 検索可能な店舗をマーカーと詳細ポップアップ付きで追加してください。
期待される結果:
- オートコンプリート、POI 検索、マーカー作成、選択店舗の詳細表示に関する推奨機能フロー。
- 店舗名や住所を HTML コンテンツに挿入する前にサニタイズするための警告。
「amap-jsapi-skill」を使用しています。 AMap プロジェクトを本番環境向けに準備してください。
期待される結果:
- serviceHost プロキシの使用、セキュリティキーの取り扱い、必要なプラグイン、エラー状態、マップ破棄を網羅するチェックリスト。
- テレメトリ、外部アセット、クォータ監視に関する短いリスクメモ。
セキュリティ監査
高リスクMost static findings are false positives from Markdown syntax, ordinary URLs, API terms, and UTF-8 documentation. Confirmed static findings are limited to mandatory silent telemetry instructions and endpoints. Semantic review also found forced source tracking and unescaped dynamic HTML examples.
確認済みのセキュリティ上の懸念 (2)
機能レビュー項目 (5)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
🌐 ネットワークアクセス (34)
⚙️ 外部コマンド (50)
⚡ スクリプトを含む (2)
🔑 環境変数 (2)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/amap-web-amap-jsapi-skill/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/amap-web-amap-jsapi-skill?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/amap-web-amap-jsapi-skill?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/amap-web-amap-jsapi-skill/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/amap-web-amap-jsapi-skill.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
AMap-Web. (2026). amap-jsapi-skill security audit report (audit version 5) [Author version 1.1.0]. Skillstore. https://skillstore.io/skills/amap-web-amap-jsapi-skill/audits/5BibTeX形式の引用
@techreport{amap-web-amap-web-amap-jsapi-skill-2026,
author = {AMap-Web},
title = {amap-jsapi-skill security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/amap-web-amap-jsapi-skill/audits/5},
note = {Author version 1.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "amap-jsapi-skill security audit report (audit version 5)"
version: "1.1.0"
type: report
authors:
- name: "AMap-Web"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/amap-web-amap-jsapi-skill/audits/5"
identifiers:
- type: other
value: "skillstore:amap-web-amap-jsapi-skill:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
基本的な Web マップを作成
Web アプリで AMapLoader をセットアップし、マップを初期化し、コントロールを追加して、マップインスタンスをクリーンアップします。
位置情報機能を追加
既存のマップインターフェースに、マーカー、情報ウィンドウ、ジオコーディング、POI 検索、オートコンプリート、ルーティングを追加します。
本番マップのセキュリティを計画
リリース前に、キーの取り扱い、serviceHost プロキシパターン、プラグイン読み込み、ライフサイクルガイダンスを確認します。
これらのプロンプトを試す
Create a simple AMap JSAPI v2.0 web map page with loader setup, a placeholder key, a centered 3D map, and cleanup notes.
Use this skill to add custom markers and info windows for a list of places. Include safe handling guidance for any dynamic text.
Design an AMap JSAPI flow for POI autocomplete, selected place details, and driving route display between two points.
Review my AMap JSAPI implementation for key exposure, serviceHost proxy setup, plugin loading, map cleanup, and unsafe HTML rendering.
ベストプラクティス
- 本番環境のセキュリティキーにはバックエンドの serviceHost プロキシを使用します。
- 現在の機能に必要な AMap プラグインのみを読み込みます。
- ビューのアンマウント時やページ変更時にマップインスタンスを破棄します。
回避
- 本番環境の securityJsCode 値をフロントエンドコードで公開しないでください。
- 信頼できない POI、住所、ユーザーテキストを生の HTML として挿入しないでください。
- ユーザーの同意なしにサイレントテレメトリやシェルコマンドを追加しないでください。