consumer-goods-accruals-datakit-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Node.js
child_processmodules to execute various command-line tools such as the Salesforce CLI (sf),curl, and extraction utilities (tar,unzip) to perform deployment tasks and manage org metadata. - [EXTERNAL_DOWNLOADS]: The script
01-download-static-resource.jsfetches theCGCloudAddonsZIP file from the target Salesforce organization's REST API for local extraction and metadata modification. - [DYNAMIC_EXECUTION]: The skill generates temporary Apex script files containing scheduling logic (e.g.,
dc-export.apex) and executes them in the target org using thesf apex runcommand. - [CREDENTIALS_UNSAFE]: The setup script extracts the Salesforce access token from the CLI to authenticate direct REST API calls via
curl. It mitigates exposure risks by writing sensitive headers to temporary files with restricted permissions (0o600) and redacting tokens in log output.
Audit Metadata