arcgis-custom-data-feeds
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of data providers that ingest content from external sources (APIs and databases). This architectural pattern creates an inherent attack surface where malicious data from these external systems could influence an agent processing the feed. The skill provides safety guards for write operations but does not explicitly implement content sanitization for ingested strings.
- Ingestion points:
getData(req)implementations inreferences/examples/editable-provider.mdandreferences/examples/minimal-provider.mdwhich utilizefetchandMongoClientto pull data. - Boundary markers: The provided code templates do not include specific delimiters or instructions to ignore embedded commands within the fetched data.
- Capability inventory: The generated providers possess network access (
fetch) and database connectivity (MongoClient) as shown in the example code. - Sanitization: The templates provide examples of mapping external data to GeoJSON properties but do not include explicit sanitization or validation of the data values themselves.
Audit Metadata