dx-devops-promote

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Salesforce CLI (sf) and jq for orchestration. Commands are structured to use record IDs as flags, explicitly avoiding unsafe string interpolation to prevent command injection.
  • [PROMPT_INJECTION]: Instructions are focused on technical workflows and do not contain patterns designed to bypass AI safety guardrails or override system prompts.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data transfer or hardcoded credentials was found. The skill operates within the authenticated context of the user's Salesforce environment.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute scripts from external, untrusted sources. All tools (sf, jq) are expected in the target environment and listed as required CLI tools in the metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:29 AM
Security Audit — agent-trust-hub — dx-devops-promote