mobile-platform-native-capabilities-integrate
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides authoritative documentation for the Salesforce mobile platform. All imports and factory functions originate from the standard
lightning/mobileCapabilitiesmodule.\n- [SAFE]: The skill promotes secure development practices by instructing users to gate every native API call behind anisAvailable()check and to handle specific failure codes for user privacy (e.g., permission denial).\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the ingestion of untrusted data from physical device sensors, which represents a potential injection surface.\n - Ingestion points: Data is ingested from the device camera and sensors via
Barcode.value(references/barcode-scanner.md),NFCRecord.payload(references/nfc.md), andDocument.text(references/document-scanner.md).\n - Boundary markers: Implementation examples in
SKILL.mddo not demonstrate the use of delimiters when processing scanned data.\n - Capability inventory: The skill includes capabilities to modify device-local data via the
ContactsService(references/contacts.md) andCalendarService(references/calendar.md).\n - Sanitization: The provided references focus on API interaction and do not specify validation or sanitization requirements for the content of the sensor payloads.
Audit Metadata