commerce-b2b-open-code-components-integrate
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches source code from the official Salesforce B2B Commerce open-source components repository on GitHub (forcedotcom). This download is from a trusted organization and follows established vendor patterns.\n- [COMMAND_EXECUTION]: Utilizes standard version control (git) and Salesforce CLI (sf) for project management, metadata retrieval, and file system organization. These operations are within the scope of a Salesforce developer workflow.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes data from local project configuration files and Salesforce org metadata to resolve paths and identify store locations.\n
- Ingestion points: Reads package directories from sfdx-project.json and lists site bundles from connected Salesforce orgs via the CLI.\n
- Boundary markers: None present in the data interpolation steps.\n
- Capability inventory: Includes git cloning, metadata retrieval from external orgs, and local file copy operations.\n
- Sanitization: Values extracted from configuration files are used for directory naming and metadata selection without explicit validation beyond structure checks.
Audit Metadata