leaflet

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Leaflet map helper with no hidden execution, credential access, persistence, or unrelated behavior found.

Reasonable to install as a Leaflet coding reference. Review generated map code for tile-provider attribution and terms, avoid hardcoding private tokens, and sanitize untrusted popup or GeoJSON property content before production use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while describing a broad set of Leaflet-related tasks in natural language, with no visible trigger boundaries or narrowing conditions. This increases the chance the agent will auto-select the skill in contexts the user did not explicitly intend, which can expand prompt surface area, cause misrouting, and let adversarial user content steer tool selection or downstream behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal