commerce-b2b-open-code-components-replace

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts exclusively with local project metadata using a restricted set of allowed tools (grep, ls, Read, Write). It does not perform any network operations or access sensitive system paths.- [SAFE]: Component replacements are strictly governed by an authoritative local mapping file (assets/ootb-to-open-code-mapping.json). This ensures that only predefined and validated 'site:' namespaces are injected into the site metadata, preventing arbitrary code or definition injection.- [SAFE]: The skill workflow incorporates user verification steps and relies on standard Salesforce development artifacts (e.g., sfdx-project.json), aligning with legitimate developer use cases without escalating privileges or establishing persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:11 PM
Security Audit — agent-trust-hub — commerce-b2b-open-code-components-replace