salesforce-developer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The DevOps reference material provides examples for setting up CI/CD pipelines that download the official Salesforce CLI binary from the Salesforce developer portal.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes patterns for handling data from external sources such as REST APIs and Salesforce Platform Events, which constitutes a managed attack surface.
  • Ingestion points: Data ingestion occurs through inbound REST resources and outbound API responses as documented in the integration patterns reference.
  • Boundary markers: The guidance instructs the agent to apply WITH SECURITY_ENFORCED and String.escapeSingleQuotes() to distinguish data from query logic.
  • Capability inventory: The skill enables database modifications and network communications via standard Apex and Salesforce CLI operations.
  • Sanitization: The provided code samples implement manual escaping and accessibility checks to sanitize data before it is persisted or used in queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — salesforce-developer