sf-flow

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Salesforce CLI (sf) for deploying metadata to authenticated Salesforce environments. This is a standard and necessary capability for the skill's primary purpose of Salesforce automation development.
  • [PROMPT_INJECTION]: A potential indirect prompt injection surface is present because the migration workflow involves reading existing Process Builder metadata files. If these files contain adversarial content in descriptions or labels, they could theoretically influence the agent's output during the generation of new Flow XML files.
  • [SAFE]: The skill actively promotes security and robustness best practices, such as implementing automation bypass logic via Custom Permissions and mandatory fault-handling connectors for all database (DML) operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 07:21 PM