omnistudio-dependencies-analyze
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by forcedotcom and operates using the official Salesforce CLI (sf). All metadata queries and processing steps align with standard Salesforce development practices.
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by parsing component metadata (JSON) from Salesforce orgs. Malicious content within the org's metadata could theoretically attempt to influence the agent's behavior during analysis. This is a characteristic of processing untrusted external data and is handled by the agent's safety layers.
Audit Metadata