dx-devops-test-suite-run
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the official Salesforce CLI (
sf) to query data and trigger test executions. All commands that modify organizational state are preceded by an explicit user confirmation prompt. - [EXTERNAL_DOWNLOADS]: Prerequisite checks include instructions to install the
@salesforce/plugin-agentplugin. This is a legitimate dependency from a well-known trusted organization (Salesforce) and is necessary for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external data such as test results and failure messages from a Salesforce org. This is handled safely through the use of human-in-the-loop confirmation gates for any downstream actions that could affect the environment.
- Ingestion points:
references/polling-configuration.md(Queries toDevopsTestSuiteExecutionandDevopsTestExecutionobjects). - Boundary markers: None explicitly defined for the ingested data.
- Capability inventory: Mutating API calls (POST) to the Salesforce Connect API and data queries via
sfCLI. - Sanitization: The instructions require the agent to present findings in plain language and avoid displaying raw JSON data to the user.
Audit Metadata