gus-cli
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill automates interactions with the Salesforce CLI ('sf') to perform data operations. It executes commands such as
sf data query,sf data create record, andsf data update recordto manage GUS work items and epics. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external Salesforce records, which presents a surface for indirect prompt injection attacks.
- Ingestion points: Data is retrieved from fields such as
Subject__c,Details__c, andDescription__cwithinADM_Work__candADM_Epic__cobjects across multiple query patterns inSKILL.md. - Boundary markers: The skill instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious commands embedded within the retrieved record content.
- Capability inventory: The skill has the capability to perform record creation, modification, and local file system access (e.g., identity caching and temporary flag files).
- Sanitization: There are no explicit requirements for sanitizing or escaping the record data before it is presented to the user or used in subsequent command construction.
- [DYNAMIC_EXECUTION]: The skill dynamically generates a configuration file in
/tmp/gus-flagsto pass complex multiline HTML data to thesfCLI via the--flags-diroption. This involves the runtime assembly of command arguments from potentially untrusted or external source data. - [DATA_EXPOSURE]: The skill extracts user metadata, including Slack IDs and GitHub logins, and stores this information in a local JSON cache at
$HOME/.claude/runner-identity.jsonto facilitate team assignments and user identification workflows.
Audit Metadata