experience-ui-bundle-mfa-configure

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses sf (Salesforce CLI) and jq for org interaction and metadata processing. Findings include queries for site metadata, user records, and deploying permission sets. These are standard administrative tasks within a Salesforce development workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Salesforce org (e.g., site names, profiles, and user lists) to drive the configuration process.
  • Ingestion points: Data enters the context via sf data query commands in SKILL.md (Steps 1, 3b, 3c, 4).
  • Boundary markers: The instructions use variable placeholders like <site-name> and <org-alias> to delimit data, though explicit 'ignore instructions' warnings for the LLM are not present.
  • Capability inventory: The skill has capabilities to write files to the local directory, deploy metadata to the org, and create/update records (User, Account, Contact) via the CLI.
  • Sanitization: There is no explicit sanitization of the string data returned from the CLI queries before interpolation into commands. However, the risk is minimal as the data is sourced from a controlled enterprise environment (Salesforce Org).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:47 AM
Security Audit — agent-trust-hub — experience-ui-bundle-mfa-configure