generating-ui-bundle-features

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes 'npx' to execute '@salesforce/ui-bundle-features', which is an official package maintained by Salesforce (forcedotcom). This is used for discovering and installing pre-built UI components.
  • [COMMAND_EXECUTION]: The instructions direct the agent to run CLI commands for listing, describing, and installing features. These commands are scoped to the Salesforce development environment and the specific project directory provided by the user.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer. The network operations are limited to standard package management via npm/npx for official vendor resources.
  • [SAFE]: The skill's behavior is consistent with its stated purpose of assisting in Salesforce UI development. The use of vendor-specific tools and the requirement for user-defined directory paths align with legitimate developer tooling practices.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:59 AM
Security Audit — agent-trust-hub — generating-ui-bundle-features