experience-content-media-stock-image-search

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script scripts/download-stock-image.py programmatically retrieves a sensitive Salesforce access token by executing the sf org auth show-access-token command.
  • [DATA_EXFILTRATION]: The helper script sends the retrieved Salesforce access token in an Authorization: Bearer header to the URL provided via the --url argument. The script lacks domain validation for this URL (only checking for https://), which allows for credential exfiltration if a malicious or redirected URL is processed by the agent.
  • [COMMAND_EXECUTION]: The skill executes local system commands through a Python helper script using subprocess.run() to interact with the Salesforce CLI (sf) and VS Code (code). Additionally, the script accepts an --output-dir argument that permits writing files to arbitrary local filesystem locations without boundary validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes search results from an external MCP server and passes data (the image URL) directly to a script with sensitive capabilities. If the external provider returns a malicious URL, the agent will execute the script with that URL, triggering the token exfiltration risk mentioned above.
  • [SAFE]: References to the Salesforce CLI (sf) and the placeholder URL on a lightning.force.com domain are consistent with the vendor's own infrastructure and are documented neutrally as intended functionality.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 07:42 AM
Security Audit — agent-trust-hub — experience-content-media-stock-image-search