consumer-goods-sync-management-configure

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the 'sf' CLI to perform operations on the Salesforce org, including SOQL queries, metadata deployment, and Apex execution. These actions are standard for Salesforce administration and follow documented CLI patterns.
  • [DYNAMIC_EXECUTION]: The skill generates temporary Apex scripts at runtime to perform batched record counts across sync-related custom settings objects. This code is executed via 'sf apex run' to verify that the installation succeeded. This dynamic behavior is strictly scoped to the skill's primary purpose of configuration verification.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically Salesforce org responses and local baseline manifests.
  • Ingestion points: Data enters the agent context through 'execute_api' results, 'sf' CLI stdout, and the 'manifest.json' file retrieved from the org.
  • Boundary markers: The skill does not explicitly use delimiters for interpolated data, but the data is primarily used for deterministic logic checks (e.g., matching IDs or counts) rather than being processed as unstructured natural language instructions.
  • Capability inventory: The skill possesses capabilities for file writing ('report.md', temporary '.apex' files) and command execution via the 'sf' CLI.
  • Sanitization: The skill relies on structured data formats (JSON) and specific, targeted SOQL queries to minimize the risk of processing unintended commands from the org data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 07:17 AM
Security Audit — agent-trust-hub — consumer-goods-sync-management-configure