field-service-data-capture-form-editor-configure

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes Flow Metadata JSON retrieved directly from a connected Salesforce environment.
  • Ingestion points: Flow metadata is ingested via the Tooling API in the Retrieve the live flow's Metadata JSON step (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or directions for the agent to disregard natural language instructions that might be embedded within the flow's metadata (e.g., in labels, descriptions, or choice values).
  • Capability inventory: The skill performs authenticated REST operations, including retrieving (GET) and updating (PATCH) flow definitions within the Salesforce org.
  • Sanitization: There is no evidence of sanitization or strict schema validation performed on the retrieved metadata before the agent interprets and modifies it based on user instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:30 PM
Security Audit — agent-trust-hub — field-service-data-capture-form-editor-configure