data360-prepare
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_SAFE]: The skill uses
.envfiles and environment variables for managing sensitive information likeCONSUMER_KEY,CONSUMER_SECRET, andPRIVATE_KEY_FILE. This follows security best practices by avoiding hardcoded credentials within scripts. - [EXTERNAL_DOWNLOADS]: The
examples/ingestion-api/README.mdfile recommends installing standard, well-known Python packages (PyJWT,cryptography,requests) viapipto support authentication and API communication. - [COMMAND_EXECUTION]: The skill utilizes the official Salesforce CLI (
sf) through thedata360plugin. Commands are executed for legitimate data operations such as listing streams (sf data360 data-stream list) and managing objects. - [REMOTE_CODE_EXECUTION]: The script
examples/ingestion-api/send-data.pyperforms a standard OAuth2 JWT Bearer Flow to authenticate with Salesforce and exchange tokens for Data Cloud access. These network operations are targeted at official Salesforce domains (login.salesforce.comand tenant-specific.c360a.salesforce.comendpoints) and represent normal vendor functionality.
Audit Metadata