integration-connectivity-generate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (configure-named-credential.sh, set-api-credential.sh) that execute Salesforce CLI commands (sf) to query data, deploy metadata, and run Apex code in the target environment.
  • [DYNAMIC_EXECUTION]: The script scripts/configure-named-credential.sh dynamically generates an Apex file containing user-provided API keys and executes it using the sf apex run command. While the script implements basic sanitization by escaping single quotes, the runtime generation and execution of code is a notable architectural pattern.
  • [INDIRECT_PROMPT_INJECTION]: As a code generation skill, it processes user requirements to create integration artifacts, presenting a potential surface for prompt injection through manipulated input.
  • Ingestion points: Processes user specifications for integration endpoints, authentication protocols, and API keys via command-line prompts and template variables.
  • Boundary markers: No explicit delimiters are present in the generation instructions to prevent the agent from obeying instructions embedded in the generated output.
  • Capability inventory: The skill has the ability to write files, deploy Salesforce metadata via CLI, and execute Apex code in a target environment.
  • Sanitization: Implements character escaping for API keys in bash scripts to mitigate Apex command injection during credential setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:01 AM
Security Audit — agent-trust-hub — integration-connectivity-generate