experience-ui-bundle-app-coordinate

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts and standardized developer tools to manage project lifecycles.
  • Evidence: Multiple bash scripts in the scripts/ directory (e.g., check-prerequisites.sh, check-sfdx-project.sh) are used for environment and project validation.
  • Evidence: SKILL.md specifies the use of sf (Salesforce CLI), npm, and npx for tasks like org authentication, dependency installation, and building the application.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it transforms natural language requests into executable code and metadata.
  • Ingestion points: User natural language requests identifying application purpose, pages, and data entities in SKILL.md (Step 1).
  • Boundary markers: The instructions do not define explicit delimiters or boundary markers for the ingested user input.
  • Capability inventory: The skill has the capability to write files, execute shell commands (npm, sf), and deploy code to a Salesforce environment.
  • Sanitization: No explicit sanitization or validation of the input prompt is described before its use in generating React code and Salesforce metadata.
  • [DYNAMIC_EXECUTION]: The skill generates and builds React source code dynamically based on user requirements.
  • Evidence: Phase 4 involves generating a complete React UI including layouts, pages, and components using templates like reactbasic.
  • Evidence: The skill executes npm run build to compile the generated source code into distribution artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 04:23 PM
Security Audit — agent-trust-hub — experience-ui-bundle-app-coordinate