mapbox
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified where the skill processes data from external API responses.
- Ingestion points: User-provided addresses and responses from
api.mapbox.comare processed inSKILL.mdwithin thegeocodeandgetRoutefunctions. - Boundary markers: No explicit boundary markers or instructions to disregard embedded commands in external data were found.
- Capability inventory: The skill examples in
SKILL.mddescribe agent capabilities such as project scaffolding and dependency installation. - Sanitization: While URL encoding is used for the API request, there is no validation or sanitization of the data returned from the API.
Audit Metadata