experience-lwr-site-generate

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Salesforce CLI (sf) and Node.js to perform operations such as site creation, metadata retrieval, deployment, and SOQL queries. These are standard operations within a Salesforce development lifecycle.
  • [DATA_EXPOSURE]: The skill involves managing metadata files like DigitalExperienceConfig and sharingGuestRules. It provides structured guidance on configuring guest user access securely within the Salesforce metadata framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user-provided input for site names, URL prefixes, and component configurations. It provides instructions to the agent to validate these inputs (e.g., alphanumeric checks for URL prefixes) to ensure they are used correctly in shell commands and metadata files.
  • [REMOTE_CODE_EXECUTION]: While the skill uses shell commands, they are directed towards established local development tools (sf, node). There are no patterns of fetching and executing arbitrary remote scripts (e.g., curl | bash).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:13 AM
Security Audit — agent-trust-hub — experience-lwr-site-generate