experience-lwc-runtime-observe

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell scripts and the Salesforce CLI to automate the setup of developer environments. It includes specific logic in scripts such as open-frontdoor.sh to handle sensitive authentication URLs securely by writing them to restricted temporary files (chmod 600) instead of the standard output stream.
  • [PROMPT_INJECTION]: The process of extracting and reading runtime DOM HTML from a browser environment introduces an indirect prompt injection surface. Maliciously crafted component content could theoretically attempt to manipulate the agent's logic.
  • Ingestion points: Runtime HTML subtree extracted via browser automation in Step 2c of SKILL.md.
  • Boundary markers: The skill uses DOM_OUTPUT_START and DOM_OUTPUT_END markers to separate external content from instructions.
  • Capability inventory: Access to shell scripts, Salesforce CLI commands, and browser automation drivers.
  • Sanitization: No HTML sanitization or filtering is performed on the extracted content prior to ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 02:01 PM
Security Audit — agent-trust-hub — experience-lwc-runtime-observe