gus-cli

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automates interactions with the Salesforce CLI ('sf') to perform data operations. It executes commands such as sf data query, sf data create record, and sf data update record to manage GUS work items and epics.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external Salesforce records, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: Data is retrieved from fields such as Subject__c, Details__c, and Description__c within ADM_Work__c and ADM_Epic__c objects across multiple query patterns in SKILL.md.
  • Boundary markers: The skill instructions do not define specific delimiters or instructions for the agent to ignore potentially malicious commands embedded within the retrieved record content.
  • Capability inventory: The skill has the capability to perform record creation, modification, and local file system access (e.g., identity caching and temporary flag files).
  • Sanitization: There are no explicit requirements for sanitizing or escaping the record data before it is presented to the user or used in subsequent command construction.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates a configuration file in /tmp/gus-flags to pass complex multiline HTML data to the sf CLI via the --flags-dir option. This involves the runtime assembly of command arguments from potentially untrusted or external source data.
  • [DATA_EXPOSURE]: The skill extracts user metadata, including Slack IDs and GitHub logins, and stores this information in a local JSON cache at $HOME/.claude/runner-identity.json to facilitate team assignments and user identification workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 10:04 AM
Security Audit — agent-trust-hub — gus-cli