salesforce-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from Salesforce (leads, contacts, accounts, and query results) which may contain adversarial instructions intended to influence the agent's behavior.
- Ingestion points: Data retrieved via tools such as
SALESFORCE_SEARCH_LEADS,SALESFORCE_LIST_CONTACTS,SALESFORCE_GET_OPPORTUNITY, andSALESFORCE_RUN_SOQL_QUERYinSKILL.mdenters the agent context. - Boundary markers: The instructions lack delimiters or specific warnings to ignore embedded instructions within the Salesforce records.
- Capability inventory: The skill possesses significant capabilities including record creation/update, ownership transfer via
SALESFORCE_MASS_TRANSFER_OWNERSHIP, and arbitrary query execution viaSALESFORCE_RUN_SOQL_QUERYacross multiple files. - Sanitization: No sanitization or validation logic is specified for the content retrieved from external Salesforce APIs.
- [EXTERNAL_DOWNLOADS]: The skill relies on a remote MCP server endpoint to provide its functionality.
- The setup instructions require adding
https://rube.app/mcpas an MCP server in the client configuration, which fetches tool schemas and facilitates tool execution through this external service.
Audit Metadata