commerce-b2b-open-code-components-replace
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts exclusively with local project metadata using a restricted set of allowed tools (grep, ls, Read, Write). It does not perform any network operations or access sensitive system paths.- [SAFE]: Component replacements are strictly governed by an authoritative local mapping file (
assets/ootb-to-open-code-mapping.json). This ensures that only predefined and validated 'site:' namespaces are injected into the site metadata, preventing arbitrary code or definition injection.- [SAFE]: The skill workflow incorporates user verification steps and relies on standard Salesforce development artifacts (e.g., sfdx-project.json), aligning with legitimate developer use cases without escalating privileges or establishing persistence.
Audit Metadata