integration-connectivity-connected-app-configure
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard command-line tools including the Salesforce CLI (
sf),curl,jq,openssl, andpython3. These are used for legitimate purposes such as metadata deployment, JWT generation, and testing OAuth flows against official Salesforce endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to review and score existing
.connectedApp-meta.xmland.eca-meta.xmlfiles. While reading local files for analysis is an inherent attack surface for indirect prompt injection, the skill defines a specific 120-point scoring framework to evaluate these files, which acts as a structured processing layer. - [EXTERNAL_DOWNLOADS]: The documentation provides examples for testing authentication using
curldirected at official Salesforce domains (login.salesforce.com,test.salesforce.com). These are well-known, trusted services within the Salesforce ecosystem. - [DATA_EXFILTRATION]: The skill explicitly instructs users and the agent to never commit consumer secrets or private keys to source control, recommending environment variables or secrets managers instead. It adheres to the principle of least privilege by discouraging the use of the 'Full' scope.
Audit Metadata