education-cloud-student-recruitment-agent-configure

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill creates and assigns administrative permission sets to the running user and a newly created service user. These actions are aligned with the skill's purpose of configuring the environment and are mitigated by mandatory human confirmation before any changes are applied.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a data ingestion surface for the configured agent. 1. Ingestion points: 'Knowledge__kav' articles and Data Cloud DMOs (grounding.md). 2. Boundary markers: None explicitly defined in the skill; relies on platform-level retriever behavior. 3. Capability inventory: User creation, PermissionSet CRUD, OWD updates, Flow management, and Agent creation ('permissions.md', 'agent-and-subagents.md', 'flows.md'). 4. Sanitization: No explicit content filtering is implemented in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:35 AM
Security Audit — agent-trust-hub — education-cloud-student-recruitment-agent-configure