arcgis-docs-lookup
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval and processing of content from external sources, which presents a potential surface for indirect instructions to enter the agent's context.
- Ingestion points: The skill instructions specify fetching content from official Esri documentation domains (developers.arcgis.com, pro.arcgis.com, enterprise.arcgis.com) and searching the
Esri/arcgis-python-apiGitHub repository (found in SKILL.md). - Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the fetched data.
- Capability inventory: The skill suggests using the
python-notebookskill for introspection and potentially escalating complex tasks to aresearchskill (found in SKILL.md). - Sanitization: The instructions do not define specific sanitization or validation steps for the retrieved external content.
- [DYNAMIC_EXECUTION]: The skill describes using Python code execution for the purpose of API verification and package introspection.
- Evidence: The instructions suggest running Python commands such as
help(Group.notify)orinspect.signature(...)within a live environment (e.g., using apython-notebookskill) to confirm API signatures when documentation pages fail to render (found in SKILL.md).
Audit Metadata