field-service-voice-to-form-configure
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes metadata from the Salesforce organization, including user identifiers and flow labels, which are used to drive administrative decisions and automated actions.
- Ingestion points: Salesforce org data retrieved via SOQL queries in SKILL.md (Step 0, Step 0.5, Step 5).
- Boundary markers: No explicit prompt delimiters or "ignore instructions" warnings are specified for the ingested metadata.
- Capability inventory: The skill performs API modifications (POST/PATCH) to settings and permissions, and uses browser-based automation to modify UI settings (SKILL.md).
- Sanitization: There is no evidence of filtering or escaping logic for the ingested strings before they are incorporated into the agent's reasoning process.
Audit Metadata