omnistudio-omniscript-generate
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
scripts/check-duplicate-omniscript.shandscripts/deploy-omniscript.sh) that execute Salesforce CLI commands. These scripts incorporate input validation using a whitelist regex (^[a-zA-Z0-9_\ ]+$) to ensure that user-provided parameters like Type, SubType, and Language are sanitized before being interpolated into SOQL queries or shell commands. - [DATA_EXPOSURE]: The
references/best-practices.mdfile contains a dedicated security section that instructs users to keep sensitive data (such as SSNs and tokens) server-side and to use masking for client-side input elements. It explicitly notes that the client-side data JSON is not a trust boundary. - [INDIRECT_PROMPT_INJECTION]: The skill processes business requirements to generate structured JSON configuration for OmniScripts.
- Ingestion points: User-provided process requirements, element labels, and logic descriptions.
- Boundary markers: Absent in the text, but the output is confined to specific Salesforce metadata schemas.
- Capability inventory: File writing (JSON assets) and shell command execution (sf CLI for data queries and project deployment).
- Sanitization: Shell scripts include regex validation for dynamic parameters; however, there is no specific NLP-level sanitization for the generated JSON content itself, which is consistent with its role as a developer tool.
Audit Metadata