experience-content-media-search

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses introspection to check its own available MCP tools (search_media_cms_channels, search_electronic_media, get_channels) to present options to the user. This is a standard functional behavior within the agent environment and does not involve executing shell commands or unauthorized code.
  • [DATA_EXPOSURE]: The skill interacts with Salesforce CMS and Data 360. It includes specific instructions to preserve all query parameters in URLs (e.g., oid, refid), which are required for authentication and CDN routing for these specific services. These parameters are handled within the context of the requested search and are not exfiltrated to unauthorized third parties.
  • [PROMPT_INJECTION]: The skill includes instructions to prevent the agent from bypassing the search source selection step. While it uses strong language ('CRITICAL', 'MUST', 'No exceptions'), these are functional constraints to ensure a specific user experience (Human-in-the-loop) rather than attempts to override safety filters or extract system prompts.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or external script downloads were detected. The skill relies entirely on pre-configured MCP tools provided by the environment.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform external downloads. It routes queries to internal search tools and asks users for URLs only in the 'Other' manual fallback scenario.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 12:17 AM
Security Audit — agent-trust-hub — experience-content-media-search