integration-connectivity-generate
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
configure-named-credential.sh,set-api-credential.sh) that execute Salesforce CLI commands (sf) to query data, deploy metadata, and run Apex code in the target environment. - [DYNAMIC_EXECUTION]: The script
scripts/configure-named-credential.shdynamically generates an Apex file containing user-provided API keys and executes it using thesf apex runcommand. While the script implements basic sanitization by escaping single quotes, the runtime generation and execution of code is a notable architectural pattern. - [INDIRECT_PROMPT_INJECTION]: As a code generation skill, it processes user requirements to create integration artifacts, presenting a potential surface for prompt injection through manipulated input.
- Ingestion points: Processes user specifications for integration endpoints, authentication protocols, and API keys via command-line prompts and template variables.
- Boundary markers: No explicit delimiters are present in the generation instructions to prevent the agent from obeying instructions embedded in the generated output.
- Capability inventory: The skill has the ability to write files, deploy Salesforce metadata via CLI, and execute Apex code in a target environment.
- Sanitization: Implements character escaping for API keys in bash scripts to mitigate Apex command injection during credential setup.
Audit Metadata