dx-org-devhub-configure

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bundled Bash script (devhub.sh) to interface with the Salesforce CLI (sf). This is the intended primary purpose of the skill to manage org configuration.
  • [SAFE]: The helper script includes a mandatory check to ensure it is invoked via an absolute path, preventing common relative path hijacking vulnerabilities.
  • [SAFE]: The skill implements a dry-run default for sensitive operations. The --apply flag is required for irreversible actions like enabling Dev Hub, and the script explicitly refuses to apply changes to an implicit default org, requiring a specific alias.
  • [SAFE]: Authentication and login flows are restricted to Salesforce-owned domains (*.salesforce.com, *.force.com, *.salesforce.mil). The script validates instance URLs to prevent redirection to malicious endpoints.
  • [SAFE]: Temporary files created during the metadata deployment process are handled using mktemp and cleaned up via shell traps. A test script (test-devhub.sh) verifies that the cleanup trap handles directory names containing special characters safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 02:01 PM
Security Audit — agent-trust-hub — dx-org-devhub-configure