experience-lwr-site-generate
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell commands, specifically the Salesforce
sfCLI for site deployment and management, andnodefor generating UUIDs. These are standard operations for Salesforce developers and are used within a utility context. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting and acting upon metadata (XML and JSON files) from the user's environment or a Salesforce organization.
- Ingestion points: Metadata files located in
sharingRules/,digitalExperiences/, and data retrieved via SOQL queries or MCP tool outputs (objectList). - Boundary markers: The skill contains explicit instructions for the agent to follow strict schemas provided by MCP tools and to adhere to specific sequential workflows.
- Capability inventory: The skill has access to deployment tools (
sf project deploy) and metadata modification tools (execute_metadata_action), allowing it to affect the target Salesforce organization. - Sanitization: The process relies on tool-based schema validation and human-in-the-loop review for UUID replacement and site creation confirmation.
Audit Metadata