automation-sandbox-post-copy-configure
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies extensively on the Bash tool to execute
sfCLI commands, includingsf org display,sf data query, andsf api request rest. These commands are used to manage Salesforce sessions, query record IDs, and perform metadata updates. - [INDIRECT_PROMPT_INJECTION]: The skill processes a user-supplied JSON configuration file (
post-copy-config.json) which dictates the automation logic, including object names, field values, and execution order. This represents a vulnerability surface where malicious configuration data could influence the agent's actions on the target Salesforce org. - Ingestion points: The
SKILL.mdworkflow (Step 1) and thescripts/plan-phases.mjsscript read and parse the configuration JSON from the local file system. - Boundary markers: The skill does not explicitly instruct the agent to ignore potentially malicious natural language instructions embedded within the JSON data fields.
- Capability inventory: The skill possesses capabilities to read from and write to a Salesforce environment using the
sfCLI and the Bash tool (PATCH, GET, and SOQL query operations). - Sanitization: The skill employs structured JSON parsing and uses specialized helper scripts (
plan-phases.mjs,map-metadata-key.mjs) to validate configuration keys and map fields before execution. - [DYNAMIC_EXECUTION]: The skill executes local JavaScript files (
.mjs) using the Node.js runtime to perform utility tasks such as planning execution phases and mapping metadata keys. These scripts use core Node.js modules and do not download external dependencies at runtime. - [DATA_EXFILTRATION]: While the skill accesses sensitive Salesforce session tokens via the
sf org displaycommand, the instructions include explicit mitigations to prevent credential leakage, such as masking tokens in summaries and avoiding the logging of authorization headers.
Audit Metadata