exb-widget
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from several sources which could potentially contain malicious instructions intended to influence agent behavior.
- Ingestion points: The skill reads local project files like
manifest.jsonandpackage.jsonand fetches remote guidance fromgithub.com/Esri/arcgis-experience-builder-sdk-resources. - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present when processing these inputs.
- Capability inventory: The skill is instructed to execute shell commands via
npm,pnpm, and custom build/test scripts defined in the workspace. - Sanitization: There is no evidence of sanitization or strict schema validation for the ingested text before it is processed.
- [EXTERNAL_DOWNLOADS]: Fetches workflow references and implementation guidance from Esri's official GitHub repository.
- [COMMAND_EXECUTION]: Directs the agent to execute environment startup, dependency installation, and production build scripts based on the local installation's configuration.
Audit Metadata