experience-lwr-site-generate

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands, specifically the Salesforce sf CLI for site deployment and management, and node for generating UUIDs. These are standard operations for Salesforce developers and are used within a utility context.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and acting upon metadata (XML and JSON files) from the user's environment or a Salesforce organization.
  • Ingestion points: Metadata files located in sharingRules/, digitalExperiences/, and data retrieved via SOQL queries or MCP tool outputs (objectList).
  • Boundary markers: The skill contains explicit instructions for the agent to follow strict schemas provided by MCP tools and to adhere to specific sequential workflows.
  • Capability inventory: The skill has access to deployment tools (sf project deploy) and metadata modification tools (execute_metadata_action), allowing it to affect the target Salesforce organization.
  • Sanitization: The process relies on tool-based schema validation and human-in-the-loop review for UUID replacement and site creation confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 08:06 AM
Security Audit — agent-trust-hub — experience-lwr-site-generate