Back to skill

Security audit

Mapbox Store Locator Patterns

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent Mapbox store-locator guidance, but its copyable examples use unsafe HTML rendering and under-disclose precise location sharing risks.

Review before installing or using this skill to generate production code. If you use it, require safe DOM construction such as textContent, createElement, setDOMContent, validated URLs, and no inline JavaScript handlers. Also add clear user-facing disclosure before requesting precise location and before sending coordinates to Mapbox for directions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:214
Finding

DOM-Based Cross-Site Scripting Through Unsanitized Store and Directions Data

Content
View full analysis
${store.properties.address}

${store.properties.phone || ''}

`; ``` The popup implementation also interpolates untrusted properties into `setHTML()`: ```javascript new mapboxgl.Popup({ closeOnClick: true }) .setLngLat(store.geometry.coordinates) .setHTML( `

${store.properties.name}

${store.properties.address}

${store.properties.phone}

${store.properties.website ? `Visit Website` : ''}` ) .addTo(map); ``` The directions reference uses the same unsafe pattern for store properties: ```javascript const popup = new mapboxgl.Popup({ closeOnClick: true }) .setLngLat(store.geometry.coordinates) .setHTML( `

${store.properties.name}

${store.properties.address}

${store.properties.phone}

${userLocation ? 'Get Directions' : ''}` ) .addTo(map); ``` Directions API response fields are also converted into HTML without escaping: ```javascript popup.setHTML( `

${store.properties.name}

${directions.distance} mi • ${directions.duration} min

${store.properties.address}

Remediation
View remediation
{ getDirections(store.properties.id); }); ``` 4. **Validate external links.** Parse website values and allow only approved protocols: ```javascript function getSafeWebsite(value) { try { const url = new URL(value); return url.protocol === 'https:' ? url.href : null; } catch { return null; } } ``` Create links throu ...[truncated 1103 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
| Geolocation & Directions | `references/geolocation-directions.md` | User location, distance calculation, route directions |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown example instructs readers to collect the user's current location and use it to calculate/store distances, but it does not mention any privacy disclosure, permission expectation, or user warning. Because markdown files should warn about behaviors affecting user data or privacy, the omission is a safety-quality issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The directions example transmits location coordinates to the Mapbox Directions API, which affects user privacy, but the surrounding markdown does not disclose that location data is sent to a third-party service. For markdown skills, network behaviors involving user data should be called out explicitly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example obtains precise user geolocation and uses it for downstream distance sorting and directions requests, but it does not show any user-facing disclosure, consent UX beyond the browser permission prompt, or explanation that coordinates may be sent to Mapbox. In a location-finder skill, this omission can lead developers to implement privacy-sensitive flows without transparency, causing unintended disclosure of users' location to a third party.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/markers.md (reported line 5)May include surrounding context.

md
## Choosing the Right Marker Strategy

| Location Count  | Strategy                               | Why                                                                                                                  |
| --------------- | -------------------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| Fewer than 100  | HTML Markers                           | Full DOM/CSS control; manageable DOM node count                                                                      |
| 100–1,000       | **Symbol Layer** (recommended default) | Renders on the **GPU via WebGL** — no DOM elements created, so performance stays smooth even with hundreds of points |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · AGENTS.md (reported line 252)May include surrounding context.

md
<meta charset="utf-8" />
    <title>Store Locator</title>
    <meta name="viewport" content="width=device-width, initial-scale=1" />
    <link href="https://api.mapbox.com/mapbox-gl-js/v3.0.0/mapbox-gl.css" rel="stylesheet" />
    <style>
      body {
        margin: 0;

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/geolocation-directions.md (reported line 103)May include surrounding context.

md
<meta charset="utf-8" />
    <title>Store Locator</title>
    <meta name="viewport" content="width=device-width, initial-scale=1" />
    <link href="https://api.mapbox.com/mapbox-gl-js/v3.0.0/mapbox-gl.css" rel="stylesheet" />
    <style>
      body {
        margin: 0;

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/styling-layout.md (reported line 12)May include surrounding context.

md
<meta charset="utf-8" />
    <title>Store Locator</title>
    <meta name="viewport" content="width=device-width, initial-scale=1" />
    <link href="https://api.mapbox.com/mapbox-gl-js/v3.0.0/mapbox-gl.css" rel="stylesheet" />
    <style>
      body {
        margin: 0;

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/styling-layout.md (reported line 186)May include surrounding context.

md
<meta charset="utf-8" />
    <title>Store Locator</title>
    <meta name="viewport" content="width=device-width, initial-scale=1" />
    <link href="https://api.mapbox.com/mapbox-gl-js/v3.0.0/mapbox-gl.css" rel="stylesheet" />
    <style>
      body {
        margin: 0;

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example uses setHTML() with interpolated store.properties fields, which can lead to DOM-based XSS if any location data is attacker-controlled or comes from a CMS, partner feed, or user submission. Because this is documentation intended for reuse, readers may copy the pattern directly into production and render untrusted data without sanitization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This clustering example again renders feature properties into popup HTML via setHTML() without sanitization, creating the same XSS risk when map feature properties originate from untrusted sources. In a store-locator context, data often comes from external feeds or admin panels, which makes unsafe documentation patterns more dangerous because they are likely to be reused widely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.