experience-ui-bundle-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of command-line tools to automate Salesforce environment setup. This includes the Salesforce CLI (sf) for metadata deployment and org configuration, Node.js (node, npm) for building project assets, and jq for processing JSON metadata files.
  • [EXTERNAL_DOWNLOADS]: As part of the standard build and GraphQL codegen processes, the skill executes npm install, which downloads third-party packages from the public npm registry into the project's uiBundles/ directories.
  • [DYNAMIC_EXECUTION]: The skill uses a template-based approach to execute administrative tasks on the Salesforce org. It populates Apex scripts (located in assets/) with project-specific values like SObject names and Account names before running them via sf apex run. It also executes a bundled JavaScript utility (prepare-import-unique-fields.js) to process data fixtures.
  • [INDIRECT_PROMPT_INJECTION]: The automation is driven by local configuration files, including org-setup.config.json and data-plan.json. The skill mitigates risks associated with untrusted configuration by instructing the agent to strictly validate API names and literals against alphanumeric whitelists before they are interpolated into Apex templates or SOQL queries.
  • [DATA_EXPOSURE]: The skill reads internal project configuration files, such as sfdx-project.json and profile metadata, to automatically derive deployment roots and license requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:11 PM
Security Audit — agent-trust-hub — experience-ui-bundle-deploy