experience-content-media-stock-image-search
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The script
scripts/download-stock-image.pyprogrammatically retrieves a sensitive Salesforce access token by executing thesf org auth show-access-tokencommand. - [DATA_EXFILTRATION]: The helper script sends the retrieved Salesforce access token in an
Authorization: Bearerheader to the URL provided via the--urlargument. The script lacks domain validation for this URL (only checking forhttps://), which allows for credential exfiltration if a malicious or redirected URL is processed by the agent. - [COMMAND_EXECUTION]: The skill executes local system commands through a Python helper script using
subprocess.run()to interact with the Salesforce CLI (sf) and VS Code (code). Additionally, the script accepts an--output-dirargument that permits writing files to arbitrary local filesystem locations without boundary validation. - [INDIRECT_PROMPT_INJECTION]: The skill processes search results from an external MCP server and passes data (the image URL) directly to a script with sensitive capabilities. If the external provider returns a malicious URL, the agent will execute the script with that URL, triggering the token exfiltration risk mentioned above.
- [SAFE]: References to the Salesforce CLI (
sf) and the placeholder URL on alightning.force.comdomain are consistent with the vendor's own infrastructure and are documented neutrally as intended functionality.
Recommendations
- AI detected serious security threats
Audit Metadata