experience-cms-brand-apply

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard implementation for Salesforce CMS branding. It follows a structured workflow (search -> confirm -> extract -> apply) that maintains user control and visibility.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves guidelines from an external source (Salesforce CMS) and instructs the agent to follow them. This is the primary purpose of the skill. The risk is mitigated by the requirement for user confirmation before a brand is applied and the use of platform-native tools to handle the content.
  • [COMMAND_EXECUTION]: No suspicious command execution patterns or shell injections were found. All tools used (search_media_cms_channels, get_brand_instructions) are scoped to CMS content management.
  • [DATA_EXFILTRATION]: No unauthorized network activity or hardcoded secrets were detected. The use of PublicUnauthenticated for the CMS channel type is documented as a requirement for CMS brand delivery and is not an indicator of exfiltration.
  • [PRIVILEGE_ESCALATION]: The skill does not attempt to acquire elevated permissions or bypass existing access controls. Error messages correctly direct users to contact administrators if permissions are lacking.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:52 AM
Security Audit — agent-trust-hub — experience-cms-brand-apply