Mapbox Cartography

Security checks across malware telemetry and agentic risk

Overview

This is a cartography guidance skill with no executable code, credential handling, persistence, or hidden high-impact behavior.

This skill appears safe to install for users who want Mapbox cartography guidance. It should be treated as design advice, not as an automated Mapbox integration, and users should still review any generated map style changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
- **Secondary:** Supporting context (water, parks)
- **Tertiary:** Background (minor roads, less important labels)

**Tools:**

- Size: Larger = more important
- Color: Brighter/saturated = more important
Confidence
85% confidence
Finding
Tools:*

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal