arcgis-online

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @membranehq/cli package from the official NPM registry. This is a vendor-provided tool required for the skill's primary functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from ArcGIS Online which could potentially contain untrusted content.
  • Ingestion points: Data is received through membrane action run, membrane action list, and membrane request commands.
  • Boundary markers: The skill does not explicitly define delimiters for untrusted data in the provided documentation.
  • Capability inventory: The agent can perform deletions, updates, and sharing operations on ArcGIS items via the CLI.
  • Sanitization: There are no explicit sanitization steps mentioned for the content retrieved from the external API.
  • [COMMAND_EXECUTION]: The skill uses the membrane CLI for all operations. These commands are restricted to the context of managing the ArcGIS integration and authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:38 AM
Security Audit — agent-trust-hub — arcgis-online