experience-lwc-legacy-migrate

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates the migration of legacy Salesforce UI stacks by guiding users to transition from Lightning Out Beta to Lightning Out 2.0. This upgrade replaces insecure hardcoded session tokens with a robust OAuth 2.0 PKCE authentication flow as a primary security improvement.
  • [SAFE]: The included Python scripts, convert-lo-names.py and validate-lo20-page.py, perform deterministic string transformations and structural validation of HTML pages. These scripts utilize standard libraries and do not perform network operations or execute arbitrary code at runtime.
  • [SAFE]: The assets/lo20-host-page-template.html serves as a secure implementation reference, implementing platform-standard communication channels (postMessage, BroadcastChannel, and localStorage) for handling authentication callbacks without exposing sensitive data.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves the agent reading and analyzing user-provided source code (Aura components and HTML host pages). While this ingestion of untrusted data presents a surface for indirect prompt injection, the skill mitigates the risk by directing the agent through pre-defined checklists and deterministic validation scripts.
  • Ingestion points: Ingestion occurs in SKILL.md (Workflow A, Step A1 and Workflow B, Step B2) when the agent reads component source files and host page HTML.
  • Boundary markers: The agent is instructed to follow specific markdown references for scoring and transformation rules.
  • Capability inventory: The agent has access to local file read/write operations and can execute the provided Python scripts.
  • Sanitization: No specific sanitization logic for ingested code is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 04:57 PM
Security Audit — agent-trust-hub — experience-lwc-legacy-migrate