experience-ui-bundle-agentforce-client-generate

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bundled shell script (detect-framework.sh) to deterministically identify whether the target project uses the React or Angular framework.
  • [COMMAND_EXECUTION]: The skill uses the Salesforce CLI (sf) to perform SOQL queries against a connected Salesforce organization to validate and resolve Agent IDs.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of official Salesforce feature packages (e.g., @salesforce/ui-bundle-template-feature-react-agentforce-conversation-client) and the Salesforce CLI via the NPM registry.
  • [PROMPT_INJECTION]: The skill includes instructions to ignore embedded instructions in data by using specific Agent ID validation rules (regex), though it does not explicitly handle untrusted external prompt data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 10:03 PM
Security Audit — agent-trust-hub — experience-ui-bundle-agentforce-client-generate