integration-connectivity-connected-app-configure

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard command-line tools including the Salesforce CLI (sf), curl, jq, openssl, and python3. These are used for legitimate purposes such as metadata deployment, JWT generation, and testing OAuth flows against official Salesforce endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to review and score existing .connectedApp-meta.xml and .eca-meta.xml files. While reading local files for analysis is an inherent attack surface for indirect prompt injection, the skill defines a specific 120-point scoring framework to evaluate these files, which acts as a structured processing layer.
  • [EXTERNAL_DOWNLOADS]: The documentation provides examples for testing authentication using curl directed at official Salesforce domains (login.salesforce.com, test.salesforce.com). These are well-known, trusted services within the Salesforce ecosystem.
  • [DATA_EXFILTRATION]: The skill explicitly instructs users and the agent to never commit consumer secrets or private keys to source control, recommending environment variables or secrets managers instead. It adheres to the principle of least privilege by discouraging the use of the 'Full' scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:38 AM
Security Audit — agent-trust-hub — integration-connectivity-connected-app-configure