experience-ui-bundle-custom-app-generate
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the project environment. It relies on user-controlled directory names in
uiBundles/and the contents ofsfdx-project.jsonto resolve core properties likeappNameandappNamespace. - Ingestion points: Project directory structure (
uiBundles/*/src/) and thesfdx-project.jsonfile are used to determine metadata values. - Boundary markers: The instructions lack specific boundary markers or warnings to the agent to ignore potentially malicious content within these files or directory names.
- Capability inventory: The skill can write new XML files to the filesystem (
applications/{appName}.app-meta.xml), modify existing XML files, and execute shell scripts. - Sanitization: There is no explicit sanitization or validation logic described for the values extracted from the project before they are used in file paths or script arguments.
- [COMMAND_EXECUTION]: The skill invokes a local shell script (
scripts/resolve-uibundle-path.sh) to determine file paths at runtime. While the script is bundled with the skill, it accepts theappNamevariable as an argument, which is derived directly from the project's directory names, creating a potential path for command injection if the agent fails to properly quote the argument during execution.
Audit Metadata