mapbox-data-visualization-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for loading and displaying external data, which establishes a surface for indirect prompt injection. \n
  • Ingestion points: External GeoJSON and Vector Tile data sources are ingested via map.addSource and map.getSource().setData() as shown in SKILL.md and references/performance.md. \n
  • Boundary markers: The instructions do not provide delimiters or warnings to the agent regarding potential instructions embedded within the data properties. \n
  • Capability inventory: The skill provides patterns for interactive UI elements such as mapboxgl.Popup and property tables (references/legends-use-cases.md) that render external feature data. \n
  • Sanitization: Code snippets directly interpolate feature properties into HTML strings without sanitization or escaping, which could allow malicious instructions in the data to be processed by an agent observing the UI output. \n- [EXTERNAL_DOWNLOADS]: The skill provides numerous patterns for fetching data from external endpoints (GeoJSON, Vector Tiles, and WebSockets) in SKILL.md, references/animation.md, and references/circles-lines.md. These are presented as implementation patterns for developers using placeholder domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:04 AM