salesforce-developer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The DevOps reference material provides examples for setting up CI/CD pipelines that download the official Salesforce CLI binary from the Salesforce developer portal.
- [INDIRECT_PROMPT_INJECTION]: The skill includes patterns for handling data from external sources such as REST APIs and Salesforce Platform Events, which constitutes a managed attack surface.
- Ingestion points: Data ingestion occurs through inbound REST resources and outbound API responses as documented in the integration patterns reference.
- Boundary markers: The guidance instructs the agent to apply
WITH SECURITY_ENFORCEDandString.escapeSingleQuotes()to distinguish data from query logic. - Capability inventory: The skill enables database modifications and network communications via standard Apex and Salesforce CLI operations.
- Sanitization: The provided code samples implement manual escaping and accessibility checks to sanitize data before it is persisted or used in queries.
Audit Metadata