field-service-data-capture-migrate
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools to perform its tasks. It utilizes
sf(Salesforce CLI) for metadata retrieval and deployment,curlfor interacting with Salesforce Tooling APIs,jqfor JSON processing, andpython3for executing the transformation and analysis scripts. These tools are standard for Salesforce development workflows. - [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and processing untrusted
.flow-meta.xmlfiles provided by the user or retrieved from an org. - Ingestion points: Multiple Python scripts (
analyze_flow.py,transform_flow.py,convert_to_dc_spec.py) parse and manipulate XML data from these external files using standard libraries. - Boundary markers: The skill does not employ specific delimiters or instructions to the agent regarding the potential for embedded malicious instructions within the XML data.
- Capability inventory: The skill possesses the capability to execute shell commands, perform file system operations (read/write/delete), and initiate network requests to Salesforce instance domains.
- Sanitization: The
transform_flow.pyscript acts as a significant security control by systematically stripping unsupported or potentially dangerous elements, such asactionCalls(Apex/invocable actions), platform event triggers, and fault connectors, ensuring the resulting output conforms to the restricted Data Capture Flow environment.
Audit Metadata