sf-soql

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is dedicated to legitimate Salesforce development tasks and demonstrates a strong security posture by prioritizing data access controls and injection prevention.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool specifically for the Salesforce CLI (sf). These commands are used to execute queries and retrieve query execution plans, which are standard operations for Salesforce developers and consistent with the skill's purpose.
  • [PROMPT_INJECTION]: No malicious patterns, bypass attempts, or instructions to ignore system safety guidelines were found in the skill metadata or body.
  • [DATA_EXFILTRATION]: No unauthorized network calls or attempts to access sensitive local files (such as SSH keys or environment secrets) were identified.
  • [CREDENTIALS_UNSAFE]: The skill does not contain hardcoded secrets and correctly assumes an existing authenticated session for the Salesforce CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 07:21 PM