arcgis-docs-lookup

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval and processing of content from external sources, which presents a potential surface for indirect instructions to enter the agent's context.
  • Ingestion points: The skill instructions specify fetching content from official Esri documentation domains (developers.arcgis.com, pro.arcgis.com, enterprise.arcgis.com) and searching the Esri/arcgis-python-api GitHub repository (found in SKILL.md).
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions within the fetched data.
  • Capability inventory: The skill suggests using the python-notebook skill for introspection and potentially escalating complex tasks to a research skill (found in SKILL.md).
  • Sanitization: The instructions do not define specific sanitization or validation steps for the retrieved external content.
  • [DYNAMIC_EXECUTION]: The skill describes using Python code execution for the purpose of API verification and package introspection.
  • Evidence: The instructions suggest running Python commands such as help(Group.notify) or inspect.signature(...) within a live environment (e.g., using a python-notebook skill) to confirm API signatures when documentation pages fail to render (found in SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:57 PM