dx-devops-test-suite-assignments-configure

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes commit diffs from the user's workspace to recommend relevant test suites. This represents an attack surface where malicious instructions embedded in code comments or metadata within the diff could attempt to influence the agent's reasoning.
  • Ingestion points: Commit diffs provided by the user or surrounding IDE context are processed in references/recommendation-logic.md.
  • Boundary markers: The instructions do not specify explicit delimiters or 'ignore' instructions for the diff content.
  • Capability inventory: The skill uses sf data query for read operations and sf api request rest for write operations (suite assignments).
  • Sanitization: No specific sanitization or filtering of the diff content is mentioned before reasoning.
  • [COMMAND_EXECUTION]: The skill uses the Salesforce CLI (sf) to perform metadata queries and API requests.
  • Evidence: Commands such as sf data query and sf api request rest are used to interact with standard Salesforce objects like DevopsPipeline and DevopsTestSuiteStage.
  • Context: These operations are restricted to the authenticated Salesforce org context and target standard platform APIs (v67.0). All mutating operations (Modes B, C, and D) require explicit user confirmation before execution, as detailed in references/suite-assignment-modes.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:49 AM
Security Audit — agent-trust-hub — dx-devops-test-suite-assignments-configure