automation-sandbox-post-copy-configure

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies extensively on the Bash tool to execute sf CLI commands, including sf org display, sf data query, and sf api request rest. These commands are used to manage Salesforce sessions, query record IDs, and perform metadata updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes a user-supplied JSON configuration file (post-copy-config.json) which dictates the automation logic, including object names, field values, and execution order. This represents a vulnerability surface where malicious configuration data could influence the agent's actions on the target Salesforce org.
  • Ingestion points: The SKILL.md workflow (Step 1) and the scripts/plan-phases.mjs script read and parse the configuration JSON from the local file system.
  • Boundary markers: The skill does not explicitly instruct the agent to ignore potentially malicious natural language instructions embedded within the JSON data fields.
  • Capability inventory: The skill possesses capabilities to read from and write to a Salesforce environment using the sf CLI and the Bash tool (PATCH, GET, and SOQL query operations).
  • Sanitization: The skill employs structured JSON parsing and uses specialized helper scripts (plan-phases.mjs, map-metadata-key.mjs) to validate configuration keys and map fields before execution.
  • [DYNAMIC_EXECUTION]: The skill executes local JavaScript files (.mjs) using the Node.js runtime to perform utility tasks such as planning execution phases and mapping metadata keys. These scripts use core Node.js modules and do not download external dependencies at runtime.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive Salesforce session tokens via the sf org display command, the instructions include explicit mitigations to prevent credential leakage, such as masking tokens in summaries and avoiding the logging of authorization headers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:33 PM
Security Audit — agent-trust-hub — automation-sandbox-post-copy-configure