arcgis-core-maps

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly loads content from public sources — e.g., CDN script tags and arbitrary service URLs, esriRequest examples, and the "Loading WebMaps and WebScenes" portalItem usage in SKILL.md (portalItem id and TileLayer/ElevationLayer URLs) — so untrusted, user-hosted WebMap/WebScene layers and fetched JSON/binary data are ingested and used to configure views/navigation, which could allow third‑party content to influence agent behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 10:23 PM