dx-devops-test-suite-assignments-configure
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes commit diffs from the user's workspace to recommend relevant test suites. This represents an attack surface where malicious instructions embedded in code comments or metadata within the diff could attempt to influence the agent's reasoning.
- Ingestion points: Commit diffs provided by the user or surrounding IDE context are processed in
references/recommendation-logic.md. - Boundary markers: The instructions do not specify explicit delimiters or 'ignore' instructions for the diff content.
- Capability inventory: The skill uses
sf data queryfor read operations andsf api request restfor write operations (suite assignments). - Sanitization: No specific sanitization or filtering of the diff content is mentioned before reasoning.
- [COMMAND_EXECUTION]: The skill uses the Salesforce CLI (
sf) to perform metadata queries and API requests. - Evidence: Commands such as
sf data queryandsf api request restare used to interact with standard Salesforce objects likeDevopsPipelineandDevopsTestSuiteStage. - Context: These operations are restricted to the authenticated Salesforce org context and target standard platform APIs (v67.0). All mutating operations (Modes B, C, and D) require explicit user confirmation before execution, as detailed in
references/suite-assignment-modes.md.
Audit Metadata