agentforce-test

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates a library of adversarial payloads (e.g., in assets/payloads/prompt-injection.yaml) designed to test agent resilience. These payloads use techniques like instruction overrides, role-play bypasses, and multi-turn manipulation to attempt to subvert the target agent's safety guidelines. These are intended for security validation.
  • [OBFUSCATION]: Some test payloads utilize encoding techniques such as Base64 to attempt to bypass safety filters (e.g., in assets/payloads/prompt-injection.yaml ID PI-002). This is included as a specific attack vector to be tested during security evaluations.
  • [DYNAMIC_EXECUTION]: The skill generates shell commands by interpolating variables such as UTTERANCE and SESSION_ID (e.g., in references/preview-testing.md). Additionally, it uses python3 -c for inline processing of CLI output. These patterns are standard for CLI-based automation tools but require careful handling of input to prevent injection.
  • [INDIRECT_PROMPT_INJECTION]: The Mode C2 assessment requires the agent to analyze and judge responses from a target agent that has been subjected to adversarial probing. This introduces a surface where the evaluation logic could be influenced by malicious content returned by the target agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:45 PM
Security Audit — agent-trust-hub — agentforce-test