mobile-platform-native-capabilities-integrate

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides authoritative documentation for the Salesforce mobile platform. All imports and factory functions originate from the standard lightning/mobileCapabilities module.\n- [SAFE]: The skill promotes secure development practices by instructing users to gate every native API call behind an isAvailable() check and to handle specific failure codes for user privacy (e.g., permission denial).\n- [INDIRECT_PROMPT_INJECTION]: The skill enables the ingestion of untrusted data from physical device sensors, which represents a potential injection surface.\n
  • Ingestion points: Data is ingested from the device camera and sensors via Barcode.value (references/barcode-scanner.md), NFCRecord.payload (references/nfc.md), and Document.text (references/document-scanner.md).\n
  • Boundary markers: Implementation examples in SKILL.md do not demonstrate the use of delimiters when processing scanned data.\n
  • Capability inventory: The skill includes capabilities to modify device-local data via the ContactsService (references/contacts.md) and CalendarService (references/calendar.md).\n
  • Sanitization: The provided references focus on API interaction and do not specify validation or sanitization requirements for the content of the sensor payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:49 AM
Security Audit — agent-trust-hub — mobile-platform-native-capabilities-integrate