experience-ui-bundle-metadata-generate
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill provides documentation and examples for configuring Salesforce UI Bundle and CSP metadata using standard Salesforce metadata formats and CLI tools.
- [SAFE]: Instructions include security best practices, such as path safety validation for configuration files to prevent directory traversal and other path-based attacks.
- [SAFE]: External URLs mentioned (e.g., Google Fonts, Unsplash, OpenStreetMap) are well-known services provided as informational examples for Content Security Policy configuration.
- [COMMAND_EXECUTION]: The skill references the standard Salesforce CLI (sf) for project scaffolding, which is an expected and legitimate developer tool for this context.
Audit Metadata