mapbox-maplibre-migration
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md is mostly clear and reviewable, though one transparency concern around a potential hardcoded credential weakens full pre-use reviewability and warrants a closer look. The skill keeps instruction and data boundaries reasonably separate and does not push the agent to treat external content as policy. Tested scenarios did not show material prompt-injection risk, but confidence is low: behavior analysis was not run, limiting the ability to assess whether loading this skill materially changes downstream behavior compared to a no-skill baseline, and the credential concern remains unresolved.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around potential hardcoded credential.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Potential hardcoded credential