mapbox-data-visualization-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for loading and displaying external data, which establishes a surface for indirect prompt injection. \n
- Ingestion points: External GeoJSON and Vector Tile data sources are ingested via
map.addSourceandmap.getSource().setData()as shown inSKILL.mdandreferences/performance.md. \n - Boundary markers: The instructions do not provide delimiters or warnings to the agent regarding potential instructions embedded within the data properties. \n
- Capability inventory: The skill provides patterns for interactive UI elements such as
mapboxgl.Popupand property tables (references/legends-use-cases.md) that render external feature data. \n - Sanitization: Code snippets directly interpolate feature properties into HTML strings without sanitization or escaping, which could allow malicious instructions in the data to be processed by an agent observing the UI output. \n- [EXTERNAL_DOWNLOADS]: The skill provides numerous patterns for fetching data from external endpoints (GeoJSON, Vector Tiles, and WebSockets) in
SKILL.md,references/animation.md, andreferences/circles-lines.md. These are presented as implementation patterns for developers using placeholder domains.
Audit Metadata