leaflet
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for the agent to ingest and render untrusted external spatial data formats including GeoJSON, GPX, and Cloud-Optimized GeoTIFFs (COG).
- Ingestion points: Example files such as
examples/geojson-choropleth.md(GeoJSON),examples/gpx-track-viewer.md(GPX), andexamples/geotiff-raster-layer.md(COG) demonstrate fetching data from remote URLs. - Capability inventory: The skill utilizes standard Leaflet rendering tools like
L.geoJSON,L.GPX, andGeoRasterLayeracross multiple implementation guides. - Boundary markers: Instructions do not explicitly specify delimiters or boundary markers for content within spatial data files (e.g., labels, metadata).
- Sanitization: The skill does not discuss sanitization for textual metadata contained within these spatial formats, which represents a theoretical surface for indirect injection if that data is displayed in popups or tooltips.
- [EXTERNAL_DOWNLOADS]: The skill references a large ecosystem of third-party Leaflet plugins and assets hosted on well-known, trusted CDNs.
- Trusted Sources: Libraries and plugins are fetched from
unpkg.com,cdnjs.cloudflare.com,cdn.jsdelivr.net, andapi.mapbox.com. - Well-Known Services: Spatial data samples and basemap services are provided by established organizations including MapTiler, NOAA, Iowa Environmental Mesonet, and the official Leaflet documentation site.
Audit Metadata