agentforce-observe
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
sf(Salesforce) CLI andbashcommands to query data, deploy metadata, and manage agent configurations. These operations are standard for Salesforce development and administration tasks. - [DATA_EXFILTRATION]: The skill accesses sensitive production data, including session traces, conversation logs, and Data Cloud records. However, all data retrieval and processing occur within the authenticated context of the user's local Salesforce CLI environment. No unauthorized external network operations or data exfiltration patterns were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted conversational data from production agents. It proactively addresses this risk by providing specific instructions and reference documentation (e.g., in
references/issue-classification.md) for detecting and mitigating prompt injection and prompt leakage in the agents being monitored. - [PRIVILEGE_ESCALATION]: The skill includes security-hardened patterns for handling temporary files. It specifically instructs the use of
mktempwithchmod 600to ensure that temporary files containing potentially sensitive organization data are restricted to the current user, mitigating risks of information disclosure in shared environments. - [REMOTE_CODE_EXECUTION]: The skill requires the deployment of a local Apex helper class (
AgentforceOptimizeService.cls) to the Salesforce organization. This class is part of the skill's local assets and is used to provide structured JSON access to Data Cloud objects. It does not download or execute unverifiable external code.
Audit Metadata