dx-org-trial-expiration-check

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands primarily through the Salesforce CLI (sf) and standard Unix utilities (jq, date). These are restricted to the allowed-tools frontmatter and are necessary for the skill's purpose of querying org metadata.
  • [SAFE]: The skill implements a human-in-the-loop pattern for potentially sensitive operations. For example, the --preserve flag only prints the necessary sf commands for backup rather than executing them automatically, ensuring the user reviews and controls the local file system impact.
  • [SAFE]: The skill enforces path safety by requiring absolute paths when invoking the bundled helper script, preventing execution of unintended scripts from the current working directory.
  • [SAFE]: Data handling is restricted to authenticated Salesforce environments using established OAuth flows. The skill does not hardcode credentials or exfiltrate data to third-party domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:48 AM
Security Audit — agent-trust-hub — dx-org-trial-expiration-check