experience-ui-bundle-salesforce-data-access
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill utilizes official Salesforce developer tools and libraries, including the '@salesforce/platform-sdk' and '@salesforce/graphiti' packages. These are verified vendor resources originating from the 'forcedotcom' organization. Standard CLI utilities such as 'sf', 'npm', and 'npx' are used appropriately within the development workflow.
- [SAFE]: The included 'graphql-search.sh' utility script follows security best practices by implementing strict input validation for entity names using a regular expression to mitigate command injection risks. Additionally, it employs controlled path resolution for the schema file to prevent directory traversal attempts.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Salesforce records (e.g., Account, Property__c) and Einstein LLM responses. (1) Ingestion points: Salesforce record data and Einstein LLM generation endpoints via 'sdk.fetch'. (2) Boundary markers: The skill mandates the use of 'gql' tags for static validation and the '@optional' directive to isolate field-level security impacts. (3) Capability inventory: GraphQL query/mutation execution, REST API interaction, and local shell execution for schema lookup. (4) Sanitization: The instructions require defensive programming patterns, specifically optional chaining and nullish coalescing, to handle missing or untrusted data safely in the UI layer. (Severity: SAFE).
Audit Metadata