dx-devops-test-failures-analyze

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of test failure messages and Code Analyzer violation payloads.
  • Ingestion points: Failure payloads and violation results are ingested for analysis in SKILL.md Part 1 and Part 2.
  • Boundary markers: While not using technical delimiters, the instructions explicitly require the agent to translate content into plain language and avoid raw data output.
  • Capability inventory: The skill is capable of performing record creation (sf data create record) in the Salesforce environment as described in references/work-item-creation.md.
  • Sanitization: The skill focuses on extracting specific fields (file name, line number, rule name) which naturally limits the impact of embedded instructions.
  • [COMMAND_EXECUTION]: The skill utilizes the sf (Salesforce CLI) for environment verification, data querying, and record creation. All commands are standard for Salesforce development and DevOps workflows.
  • [EXTERNAL_DOWNLOADS]: The references/prerequisite-checks.md file includes instructions to install the @salesforce/plugin-agent plugin. This is a standard extension for the Salesforce CLI provided by the vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 03:37 AM
Security Audit — agent-trust-hub — dx-devops-test-failures-analyze