experience-ui-bundle-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of command-line tools to automate Salesforce environment setup. This includes the Salesforce CLI (
sf) for metadata deployment and org configuration, Node.js (node,npm) for building project assets, andjqfor processing JSON metadata files. - [EXTERNAL_DOWNLOADS]: As part of the standard build and GraphQL codegen processes, the skill executes
npm install, which downloads third-party packages from the public npm registry into the project'suiBundles/directories. - [DYNAMIC_EXECUTION]: The skill uses a template-based approach to execute administrative tasks on the Salesforce org. It populates Apex scripts (located in
assets/) with project-specific values like SObject names and Account names before running them viasf apex run. It also executes a bundled JavaScript utility (prepare-import-unique-fields.js) to process data fixtures. - [INDIRECT_PROMPT_INJECTION]: The automation is driven by local configuration files, including
org-setup.config.jsonanddata-plan.json. The skill mitigates risks associated with untrusted configuration by instructing the agent to strictly validate API names and literals against alphanumeric whitelists before they are interpolated into Apex templates or SOQL queries. - [DATA_EXPOSURE]: The skill reads internal project configuration files, such as
sfdx-project.jsonand profile metadata, to automatically derive deployment roots and license requirements.
Audit Metadata