salesforce-developer
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a structured reference guide and instructional tool for Salesforce development, containing no executable malicious code or prompt injection triggers.
- [SAFE]: Integration patterns correctly leverage Salesforce Named Credentials (
callout:...), ensuring that authentication details are managed securely within the platform rather than being hardcoded in scripts. - [SAFE]: Dynamic SOQL examples include appropriate sanitization via
String.escapeSingleQuotes()and utilize theWITH SECURITY_ENFORCEDclause to ensure compliance with object and field-level security settings. - [SAFE]: Documentation for CI/CD pipelines (GitHub Actions and GitLab CI) follows security best practices by referencing environment secrets (e.g.,
${{ secrets.SFDX_AUTH_URL }}) instead of exposing sensitive authentication tokens in plain text. - [SAFE]: External downloads and dependencies originate from trusted sources, such as the official Salesforce developer portal (
developer.salesforce.com) and well-known, widely-used integration libraries (jsforce,cometd). - [SAFE]: Sandbox management scripts include data masking patterns (e.g., anonymizing email addresses), which is a critical security practice for protecting user privacy in non-production environments.
Audit Metadata