apex-language
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references external ANTLR grammar files (
BaseApexParser.g4andBaseApexLexer.g4) hosted in theapex-dev-toolsGitHub repository to guide the implementation of parser listeners. - [INDIRECT_PROMPT_INJECTION]: Because the skill is designed to ingest and interpret Apex source files (.cls, .trigger, .apex) to build symbol tables and perform semantic analysis, it possesses a vulnerability surface where instructions embedded in code comments or metadata could attempt to influence the agent's logic.
- Ingestion points: Apex source code is passed to the
CompilerService.compilemethod as described in theSKILL.mdfile. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" prompts for the untrusted code being processed.
- Capability inventory: The skill enables the creation of listeners that build symbol tables, resolve references, and report validation errors, which are then used by the language server infrastructure.
- Sanitization: No explicit sanitization or filtering of external source content is mentioned before the parsing phase.
- [COMMAND_EXECUTION]: The documentation instructs the agent to execute
npm run precompileto regenerate TypeScript files from configuration properties, which is a standard project build operation.
Audit Metadata