experience-ui-bundle-mfa-configure
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
sf(Salesforce CLI) andjqfor org interaction and metadata processing. Findings include queries for site metadata, user records, and deploying permission sets. These are standard administrative tasks within a Salesforce development workflow. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the Salesforce org (e.g., site names, profiles, and user lists) to drive the configuration process.
- Ingestion points: Data enters the context via
sf data querycommands inSKILL.md(Steps 1, 3b, 3c, 4). - Boundary markers: The instructions use variable placeholders like
<site-name>and<org-alias>to delimit data, though explicit 'ignore instructions' warnings for the LLM are not present. - Capability inventory: The skill has capabilities to write files to the local directory, deploy metadata to the org, and create/update records (User, Account, Contact) via the CLI.
- Sanitization: There is no explicit sanitization of the string data returned from the CLI queries before interpolation into commands. However, the risk is minimal as the data is sourced from a controlled enterprise environment (Salesforce Org).
Audit Metadata