dx-devops-test-suite-run

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the official Salesforce CLI (sf) to query data and trigger test executions. All commands that modify organizational state are preceded by an explicit user confirmation prompt.
  • [EXTERNAL_DOWNLOADS]: Prerequisite checks include instructions to install the @salesforce/plugin-agent plugin. This is a legitimate dependency from a well-known trusted organization (Salesforce) and is necessary for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external data such as test results and failure messages from a Salesforce org. This is handled safely through the use of human-in-the-loop confirmation gates for any downstream actions that could affect the environment.
  • Ingestion points: references/polling-configuration.md (Queries to DevopsTestSuiteExecution and DevopsTestExecution objects).
  • Boundary markers: None explicitly defined for the ingested data.
  • Capability inventory: Mutating API calls (POST) to the Salesforce Connect API and data queries via sf CLI.
  • Sanitization: The instructions require the agent to present findings in plain language and avoid displaying raw JSON data to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:49 AM
Security Audit — agent-trust-hub — dx-devops-test-suite-run