leaflet

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for the agent to ingest and render untrusted external spatial data formats including GeoJSON, GPX, and Cloud-Optimized GeoTIFFs (COG).
  • Ingestion points: Example files such as examples/geojson-choropleth.md (GeoJSON), examples/gpx-track-viewer.md (GPX), and examples/geotiff-raster-layer.md (COG) demonstrate fetching data from remote URLs.
  • Capability inventory: The skill utilizes standard Leaflet rendering tools like L.geoJSON, L.GPX, and GeoRasterLayer across multiple implementation guides.
  • Boundary markers: Instructions do not explicitly specify delimiters or boundary markers for content within spatial data files (e.g., labels, metadata).
  • Sanitization: The skill does not discuss sanitization for textual metadata contained within these spatial formats, which represents a theoretical surface for indirect injection if that data is displayed in popups or tooltips.
  • [EXTERNAL_DOWNLOADS]: The skill references a large ecosystem of third-party Leaflet plugins and assets hosted on well-known, trusted CDNs.
  • Trusted Sources: Libraries and plugins are fetched from unpkg.com, cdnjs.cloudflare.com, cdn.jsdelivr.net, and api.mapbox.com.
  • Well-Known Services: Spatial data samples and basemap services are provided by established organizations including MapTiler, NOAA, Iowa Environmental Mesonet, and the official Leaflet documentation site.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:05 PM
Security Audit — agent-trust-hub — leaflet