experience-lwc-runtime-observe
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell scripts and the Salesforce CLI to automate the setup of developer environments. It includes specific logic in scripts such as open-frontdoor.sh to handle sensitive authentication URLs securely by writing them to restricted temporary files (chmod 600) instead of the standard output stream.
- [PROMPT_INJECTION]: The process of extracting and reading runtime DOM HTML from a browser environment introduces an indirect prompt injection surface. Maliciously crafted component content could theoretically attempt to manipulate the agent's logic.
- Ingestion points: Runtime HTML subtree extracted via browser automation in Step 2c of SKILL.md.
- Boundary markers: The skill uses DOM_OUTPUT_START and DOM_OUTPUT_END markers to separate external content from instructions.
- Capability inventory: Access to shell scripts, Salesforce CLI commands, and browser automation drivers.
- Sanitization: No HTML sanitization or filtering is performed on the extracted content prior to ingestion.
Audit Metadata