automation-flow-generate

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a defined MCP tool execute_metadata_action provided by the vendor to perform metadata-related tasks. All documented operations occur within the intended scope of Salesforce automation development.
  • [SAFE]: The instruction to use an empty array [] for secret/metadata placeholders is a safe practice that prevents unintended data transmission.
  • [SAFE]: The pipeline architecture (fetch -> select -> generate) ensures that the agent does not attempt to manually fabricate XML, which reduces the risk of generating invalid or malicious metadata structures.
  • [SAFE]: Data ingestion from the local sfdx project is scoped to custom object and field metadata necessary for flow generation, which is standard for development tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 06:32 PM
Security Audit — agent-trust-hub — automation-flow-generate