agentforce-architecture-analyze
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the Salesforce CLI (sf) to retrieve organization details and metadata. These subprocess calls are implemented in scripts/sf_cli.py, scripts/resolve_bot.py, and scripts/metadata_listing.py using list-based arguments without a shell, which mitigates command injection risks.
- [EXTERNAL_DOWNLOADS]: Communication with Salesforce API domains (e.g., *.salesforce.com) is performed to fetch agent architecture data. This is managed by a secure REST client in scripts/rest_client.py that includes a custom redirect handler to prevent credential leakage to external hosts.
- [SAFE]: The skill uses a comprehensive validation layer in scripts/_shared/fs_guard.py and scripts/soql_loader.py. All user-provided strings and metadata identifiers are validated against strict regular expressions before being used in SOQL queries, CLI arguments, or filesystem paths.
Audit Metadata