dx-org-manage

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the bash tool to execute sf CLI commands for Salesforce scratch org and snapshot management. It also invokes a provided bash script, assets/derive-alias.sh, which performs alias derivation and collision checks by querying existing orgs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data to construct CLI commands and author JSON configuration files, creating a potential surface for indirect prompt injection.
  • Ingestion points: User-provided strings for aliases, source org IDs, snapshot names, and Salesforce features or settings are ingested via natural language prompts.
  • Boundary markers: The instructions do not define boundary markers or delimiters for the interpolation of these user-provided strings into shell commands or authored definition files.
  • Capability inventory: The skill has the capability to execute org lifecycle commands (create, delete, list) and write files (scratch-org definition files and results) within the project directory via the bash tool.
  • Sanitization: A local helper script (assets/derive-alias.sh) sanitizes aliases using a slugification process (lowercase, non-alphanumeric conversion). For other identifiers like org IDs, the skill relies on the validation logic provided by the sf CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 04:23 PM
Security Audit — agent-trust-hub — dx-org-manage