experience-ui-bundle-custom-app-generate

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the project environment. It relies on user-controlled directory names in uiBundles/ and the contents of sfdx-project.json to resolve core properties like appName and appNamespace.
  • Ingestion points: Project directory structure (uiBundles/*/src/) and the sfdx-project.json file are used to determine metadata values.
  • Boundary markers: The instructions lack specific boundary markers or warnings to the agent to ignore potentially malicious content within these files or directory names.
  • Capability inventory: The skill can write new XML files to the filesystem (applications/{appName}.app-meta.xml), modify existing XML files, and execute shell scripts.
  • Sanitization: There is no explicit sanitization or validation logic described for the values extracted from the project before they are used in file paths or script arguments.
  • [COMMAND_EXECUTION]: The skill invokes a local shell script (scripts/resolve-uibundle-path.sh) to determine file paths at runtime. While the script is bundled with the skill, it accepts the appName variable as an argument, which is derived directly from the project's directory names, creating a potential path for command injection if the agent fails to properly quote the argument during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:29 AM
Security Audit — agent-trust-hub — experience-ui-bundle-custom-app-generate