experience-ui-bundle-salesforce-data-access

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill utilizes official Salesforce developer tools and libraries, including the '@salesforce/platform-sdk' and '@salesforce/graphiti' packages. These are verified vendor resources originating from the 'forcedotcom' organization. Standard CLI utilities such as 'sf', 'npm', and 'npx' are used appropriately within the development workflow.
  • [SAFE]: The included 'graphql-search.sh' utility script follows security best practices by implementing strict input validation for entity names using a regular expression to mitigate command injection risks. Additionally, it employs controlled path resolution for the schema file to prevent directory traversal attempts.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Salesforce records (e.g., Account, Property__c) and Einstein LLM responses. (1) Ingestion points: Salesforce record data and Einstein LLM generation endpoints via 'sdk.fetch'. (2) Boundary markers: The skill mandates the use of 'gql' tags for static validation and the '@optional' directive to isolate field-level security impacts. (3) Capability inventory: GraphQL query/mutation execution, REST API interaction, and local shell execution for schema lookup. (4) Sanitization: The instructions require defensive programming patterns, specifically optional chaining and nullish coalescing, to handle missing or untrusted data safely in the UI layer. (Severity: SAFE).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:13 PM
Security Audit — agent-trust-hub — experience-ui-bundle-salesforce-data-access