openlayers
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions in SKILL.md and the example prompts in references/prompt-benchmarks.md were analyzed. No instructions attempting to bypass safety filters, override agent persona, or disregard system constraints were found. The mandatory workflows are standard for high-quality developer assistance skills.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, API keys, or sensitive file paths were detected. The skill correctly uses placeholders like 'YOUR_API_KEY' for MapTiler integration and includes proactive instructions for users to acquire their own keys from official sources.
- [OBFUSCATION]: A thorough scan for Base64, zero-width characters, homoglyphs, and hex escapes was performed across all 82 files. No obfuscation techniques were identified; all code snippets and documentation are in plain, human-readable text.
- [EXTERNAL_DOWNLOADS]: The skill references standard, well-known CDN providers (jsDelivr, unpkg, cdnjs) and official repositories (MapTiler, OpenLayers, Sentinel Hub). These downloads are for legitimate mapping libraries and data samples.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill provides functionality to load external spatial data files such as GeoJSON, KML, and GPX (e.g., examples/drag-and-drop.md, examples/geojson-choropleth.md).
- Boundary markers: Not explicitly required by the agent instructions, though structured parsing is handled by the OpenLayers library.
- Capability inventory: The skill uses fetch() to retrieve remote map data and OGC service capabilities (e.g., references/ogc-wms-wmts-wfs.md).
- Sanitization: Standard library parsers (ol/format/*) are used for data ingestion. Given that loading external map data is the primary intended purpose of the skill, this represents an expected operational surface rather than a security risk.
Audit Metadata