maplibre

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the MapLibre library and specialized plugins (e.g., Mapbox GL Draw, Turf.js, Three.js) from established content delivery networks such as unpkg.com, jsdelivr.net, and official Mapbox/MapTiler domains. These resources are necessary for the skill's primary function and come from well-known technology providers.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Several examples (e.g., click-select-highlight.md, cluster-spiderfy.md) demonstrate fetching GeoJSON data from external repositories like GitHub and official government sources (USGS).
  • Boundary markers: Absent; data is typically loaded directly into the mapping engine for rendering.
  • Capability inventory: Includes map.addSource and map.setData to update mapping data structures. The scripts perform no arbitrary code execution on the ingested data.
  • Sanitization: Data is processed and rendered by the MapLibre WebGL engine, which acts as a sandbox for geographic primitives.
  • [SAFE]: The skill follows security best practices by using placeholders for API keys (e.g., YOUR_MAPTILER_KEY) and providing explicit instructions on how users should manage their own secrets in environment variables. No hardcoded credentials, persistence mechanisms, or unauthorized network operations were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:05 PM
Security Audit — agent-trust-hub — maplibre