integrating-b2b-commerce-open-code-components

Pass

Audited by Gen Agent Trust Hub on May 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill downloads content from a trusted repository (github.com/forcedotcom/b2b-commerce-open-source-components). The operations are consistent with the skill's stated purpose of integrating official vendor components.
  • [COMMAND_EXECUTION]: The skill utilizes git clone, cp, and Salesforce CLI (sf) commands. These operations are restricted to project metadata management and are appropriately scoped within the allowed-tools configuration.
  • [EXTERNAL_DOWNLOADS]: Fetches configuration and code components from the official Salesforce repository. This is a primary function of the skill and targets a well-known vendor service.
Audit Metadata
Risk Level
SAFE
Analyzed
May 29, 2026, 02:37 AM
Security Audit — agent-trust-hub — integrating-b2b-commerce-open-code-components