agentforce-test
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates a library of adversarial payloads (e.g., in assets/payloads/prompt-injection.yaml) designed to test agent resilience. These payloads use techniques like instruction overrides, role-play bypasses, and multi-turn manipulation to attempt to subvert the target agent's safety guidelines. These are intended for security validation.
- [OBFUSCATION]: Some test payloads utilize encoding techniques such as Base64 to attempt to bypass safety filters (e.g., in assets/payloads/prompt-injection.yaml ID PI-002). This is included as a specific attack vector to be tested during security evaluations.
- [DYNAMIC_EXECUTION]: The skill generates shell commands by interpolating variables such as UTTERANCE and SESSION_ID (e.g., in references/preview-testing.md). Additionally, it uses python3 -c for inline processing of CLI output. These patterns are standard for CLI-based automation tools but require careful handling of input to prevent injection.
- [INDIRECT_PROMPT_INJECTION]: The Mode C2 assessment requires the agent to analyze and judge responses from a target agent that has been subjected to adversarial probing. This introduces a surface where the evaluation logic could be influenced by malicious content returned by the target agent.
Audit Metadata