dx-org-devhub-configure
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bundled Bash script (
devhub.sh) to interface with the Salesforce CLI (sf). This is the intended primary purpose of the skill to manage org configuration. - [SAFE]: The helper script includes a mandatory check to ensure it is invoked via an absolute path, preventing common relative path hijacking vulnerabilities.
- [SAFE]: The skill implements a dry-run default for sensitive operations. The
--applyflag is required for irreversible actions like enabling Dev Hub, and the script explicitly refuses to apply changes to an implicit default org, requiring a specific alias. - [SAFE]: Authentication and login flows are restricted to Salesforce-owned domains (
*.salesforce.com,*.force.com,*.salesforce.mil). The script validates instance URLs to prevent redirection to malicious endpoints. - [SAFE]: Temporary files created during the metadata deployment process are handled using
mktempand cleaned up via shell traps. A test script (test-devhub.sh) verifies that the cleanup trap handles directory names containing special characters safely.
Audit Metadata