ClawAudit verdict
mapbox-web-integration-patterns
Mapbox GL JS integration patterns skill providing framework-specific setup guides; primarily documentation with package installation for legitimate map integration development.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
file_read
credential_access
package_install
Findings (4)
<script> tag in markdown โ potential code injection
SKILL.md ยท code ยท <script
Possible hardcoded credential
references/common-mistakes.md ยท code ยท Token = 'pk.YOUR_MAPBOX_TOKEN_HERE
Dynamic import() โ loads module at runtime
AGENTS.md ยท code ยท import('
Accesses sensitive environment variables
references/nextjs.md ยท code ยท process.env.NEXT_PUBLIC_MAPBOX_TOKEN
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_installcredential_accessfile_read Is this flag fair?
Thanks โ recorded.