integrating-b2b-commerce-open-code-components
Pass
Audited by Gen Agent Trust Hub on May 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill downloads content from a trusted repository (github.com/forcedotcom/b2b-commerce-open-source-components). The operations are consistent with the skill's stated purpose of integrating official vendor components.
- [COMMAND_EXECUTION]: The skill utilizes
git clone,cp, and Salesforce CLI (sf) commands. These operations are restricted to project metadata management and are appropriately scoped within theallowed-toolsconfiguration. - [EXTERNAL_DOWNLOADS]: Fetches configuration and code components from the official Salesforce repository. This is a primary function of the skill and targets a well-known vendor service.
Audit Metadata