maplibre
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the MapLibre library and specialized plugins (e.g., Mapbox GL Draw, Turf.js, Three.js) from established content delivery networks such as unpkg.com, jsdelivr.net, and official Mapbox/MapTiler domains. These resources are necessary for the skill's primary function and come from well-known technology providers.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Several examples (e.g.,
click-select-highlight.md,cluster-spiderfy.md) demonstrate fetching GeoJSON data from external repositories like GitHub and official government sources (USGS). - Boundary markers: Absent; data is typically loaded directly into the mapping engine for rendering.
- Capability inventory: Includes
map.addSourceandmap.setDatato update mapping data structures. The scripts perform no arbitrary code execution on the ingested data. - Sanitization: Data is processed and rendered by the MapLibre WebGL engine, which acts as a sandbox for geographic primitives.
- [SAFE]: The skill follows security best practices by using placeholders for API keys (e.g.,
YOUR_MAPTILER_KEY) and providing explicit instructions on how users should manage their own secrets in environment variables. No hardcoded credentials, persistence mechanisms, or unauthorized network operations were detected.
Audit Metadata