exb-widget

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard developer guidance for ArcGIS Experience Builder. It emphasizes version alignment between the Developer Edition and ArcGIS Enterprise environments, and validates manifest file invariants.
  • [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to read local project metadata from client/package.json to determine the software version.
  • Ingestion points: Reads client/package.json (SKILL.md).
  • Boundary markers: None explicitly defined for the file content.
  • Capability inventory: The skill describes developer tasks using npm and pnpm but does not automatically execute commands based on the file content.
  • Sanitization: None described.
  • Risk: This constitutes a standard data ingestion point for a developer tool; the risk is minimal as it targets local configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 06:24 PM
Security Audit — agent-trust-hub — exb-widget