dx-devops-test-failures-analyze
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of test failure messages and Code Analyzer violation payloads.
- Ingestion points: Failure payloads and violation results are ingested for analysis in SKILL.md Part 1 and Part 2.
- Boundary markers: While not using technical delimiters, the instructions explicitly require the agent to translate content into plain language and avoid raw data output.
- Capability inventory: The skill is capable of performing record creation (sf data create record) in the Salesforce environment as described in references/work-item-creation.md.
- Sanitization: The skill focuses on extracting specific fields (file name, line number, rule name) which naturally limits the impact of embedded instructions.
- [COMMAND_EXECUTION]: The skill utilizes the sf (Salesforce CLI) for environment verification, data querying, and record creation. All commands are standard for Salesforce development and DevOps workflows.
- [EXTERNAL_DOWNLOADS]: The references/prerequisite-checks.md file includes instructions to install the @salesforce/plugin-agent plugin. This is a standard extension for the Salesforce CLI provided by the vendor.
Audit Metadata