platform-agenticsetup-categories-get

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the sf (Salesforce CLI) tool via the Bash tool to perform organization connectivity checks (sf org display) and execute REST API requests (sf api request rest). These operations are consistent with the skill's stated purpose of retrieving metadata from a connected Salesforce instance.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external Salesforce API responses, which may contain user-defined text in fields like label, text, and description. This creates a potential surface for indirect prompt injection if the retrieved content contains malicious instructions intended to influence the agent's subsequent behavior.
  • Ingestion points: Data is retrieved from the /services/data/vXX.0/agenticsetup/categories REST endpoint via the sf CLI and presented in the final output.
  • Boundary markers: The instructions do not specify the use of clear delimiters (e.g., XML tags or triple quotes) or "ignore embedded instructions" warnings when presenting the API content to the agent or user.
  • Capability inventory: The skill has access to the Bash tool for command execution and the Read tool for accessing local files.
  • Sanitization: There are no instructions for sanitizing or validating the content retrieved from the API before it is processed or displayed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:46 PM
Security Audit — agent-trust-hub — platform-agenticsetup-categories-get