omnistudio-omniscript-generate

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (scripts/check-duplicate-omniscript.sh and scripts/deploy-omniscript.sh) that execute Salesforce CLI commands. These scripts incorporate input validation using a whitelist regex (^[a-zA-Z0-9_\ ]+$) to ensure that user-provided parameters like Type, SubType, and Language are sanitized before being interpolated into SOQL queries or shell commands.
  • [DATA_EXPOSURE]: The references/best-practices.md file contains a dedicated security section that instructs users to keep sensitive data (such as SSNs and tokens) server-side and to use masking for client-side input elements. It explicitly notes that the client-side data JSON is not a trust boundary.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes business requirements to generate structured JSON configuration for OmniScripts.
  • Ingestion points: User-provided process requirements, element labels, and logic descriptions.
  • Boundary markers: Absent in the text, but the output is confined to specific Salesforce metadata schemas.
  • Capability inventory: File writing (JSON assets) and shell command execution (sf CLI for data queries and project deployment).
  • Sanitization: Shell scripts include regex validation for dynamic parameters; however, there is no specific NLP-level sanitization for the generated JSON content itself, which is consistent with its role as a developer tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 02:13 AM
Security Audit — agent-trust-hub — omnistudio-omniscript-generate