data360-prepare

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_SAFE]: The skill uses .env files and environment variables for managing sensitive information like CONSUMER_KEY, CONSUMER_SECRET, and PRIVATE_KEY_FILE. This follows security best practices by avoiding hardcoded credentials within scripts.
  • [EXTERNAL_DOWNLOADS]: The examples/ingestion-api/README.md file recommends installing standard, well-known Python packages (PyJWT, cryptography, requests) via pip to support authentication and API communication.
  • [COMMAND_EXECUTION]: The skill utilizes the official Salesforce CLI (sf) through the data360 plugin. Commands are executed for legitimate data operations such as listing streams (sf data360 data-stream list) and managing objects.
  • [REMOTE_CODE_EXECUTION]: The script examples/ingestion-api/send-data.py performs a standard OAuth2 JWT Bearer Flow to authenticate with Salesforce and exchange tokens for Data Cloud access. These network operations are targeted at official Salesforce domains (login.salesforce.com and tenant-specific .c360a.salesforce.com endpoints) and represent normal vendor functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:29 AM
Security Audit — agent-trust-hub — data360-prepare