salesforce-developer

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a structured reference guide and instructional tool for Salesforce development, containing no executable malicious code or prompt injection triggers.
  • [SAFE]: Integration patterns correctly leverage Salesforce Named Credentials (callout:...), ensuring that authentication details are managed securely within the platform rather than being hardcoded in scripts.
  • [SAFE]: Dynamic SOQL examples include appropriate sanitization via String.escapeSingleQuotes() and utilize the WITH SECURITY_ENFORCED clause to ensure compliance with object and field-level security settings.
  • [SAFE]: Documentation for CI/CD pipelines (GitHub Actions and GitLab CI) follows security best practices by referencing environment secrets (e.g., ${{ secrets.SFDX_AUTH_URL }}) instead of exposing sensitive authentication tokens in plain text.
  • [SAFE]: External downloads and dependencies originate from trusted sources, such as the official Salesforce developer portal (developer.salesforce.com) and well-known, widely-used integration libraries (jsforce, cometd).
  • [SAFE]: Sandbox management scripts include data masking patterns (e.g., anonymizing email addresses), which is a critical security practice for protecting user privacy in non-production environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 04:50 PM
Security Audit — agent-trust-hub — salesforce-developer