dx-org-manage
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
bashtool to executesfCLI commands for Salesforce scratch org and snapshot management. It also invokes a provided bash script,assets/derive-alias.sh, which performs alias derivation and collision checks by querying existing orgs. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data to construct CLI commands and author JSON configuration files, creating a potential surface for indirect prompt injection.
- Ingestion points: User-provided strings for aliases, source org IDs, snapshot names, and Salesforce features or settings are ingested via natural language prompts.
- Boundary markers: The instructions do not define boundary markers or delimiters for the interpolation of these user-provided strings into shell commands or authored definition files.
- Capability inventory: The skill has the capability to execute org lifecycle commands (create, delete, list) and write files (scratch-org definition files and results) within the project directory via the
bashtool. - Sanitization: A local helper script (
assets/derive-alias.sh) sanitizes aliases using a slugification process (lowercase, non-alphanumeric conversion). For other identifiers like org IDs, the skill relies on the validation logic provided by thesfCLI tool.
Audit Metadata