omnistudio-dependencies-analyze

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is performing inventory and dependency analysis of OmniStudio components (OmniScripts, FlexCards, Integration Procedures, and Data Mappers).
  • [COMMAND_EXECUTION]: Uses the official Salesforce CLI (sf) to perform metadata queries. The commands are standard SOQL probes (sf data query) used to detect which Salesforce namespace (Core, vlocity_cmt, or vlocity_ins) is active in the target org.
  • [DATA_EXPOSURE_&_EXFILTRATION]: No evidence of data exfiltration or unauthorized access. All queries target OmniStudio configuration metadata objects. The skill does not access sensitive local file paths like .ssh, .aws, or .env files.
  • [PROMPT_INJECTION]: The instructions do not contain markers intended to bypass safety guidelines, override agent behavior, or extract system prompts. Instructional language like "CRITICAL: Orchestration Order" refers to the sequence of operations for technical analysis rather than an attempt to override AI constraints.
  • [REMOTE_CODE_EXECUTION]: No external code is downloaded or executed. The skill relies entirely on pre-installed CLI tools and built-in analytical logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface (parsing OmniStudio JSON metadata fields like PropertySetConfig). However, the analysis is limited to extracting specific keys for dependency mapping. There are no high-privilege write operations or shell execution paths that consume this external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 02:13 AM
Security Audit — agent-trust-hub — omnistudio-dependencies-analyze