field-service-data-capture-migrate

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools to perform its tasks. It utilizes sf (Salesforce CLI) for metadata retrieval and deployment, curl for interacting with Salesforce Tooling APIs, jq for JSON processing, and python3 for executing the transformation and analysis scripts. These tools are standard for Salesforce development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and processing untrusted .flow-meta.xml files provided by the user or retrieved from an org.
  • Ingestion points: Multiple Python scripts (analyze_flow.py, transform_flow.py, convert_to_dc_spec.py) parse and manipulate XML data from these external files using standard libraries.
  • Boundary markers: The skill does not employ specific delimiters or instructions to the agent regarding the potential for embedded malicious instructions within the XML data.
  • Capability inventory: The skill possesses the capability to execute shell commands, perform file system operations (read/write/delete), and initiate network requests to Salesforce instance domains.
  • Sanitization: The transform_flow.py script acts as a significant security control by systematically stripping unsupported or potentially dangerous elements, such as actionCalls (Apex/invocable actions), platform event triggers, and fault connectors, ensuring the resulting output conforms to the restricted Data Capture Flow environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:56 PM
Security Audit — agent-trust-hub — field-service-data-capture-migrate