platform-agenticsetup-categories-get
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
sf(Salesforce CLI) tool via theBashtool to perform organization connectivity checks (sf org display) and execute REST API requests (sf api request rest). These operations are consistent with the skill's stated purpose of retrieving metadata from a connected Salesforce instance. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external Salesforce API responses, which may contain user-defined text in fields like
label,text, anddescription. This creates a potential surface for indirect prompt injection if the retrieved content contains malicious instructions intended to influence the agent's subsequent behavior. - Ingestion points: Data is retrieved from the
/services/data/vXX.0/agenticsetup/categoriesREST endpoint via thesfCLI and presented in the final output. - Boundary markers: The instructions do not specify the use of clear delimiters (e.g., XML tags or triple quotes) or "ignore embedded instructions" warnings when presenting the API content to the agent or user.
- Capability inventory: The skill has access to the
Bashtool for command execution and theReadtool for accessing local files. - Sanitization: There are no instructions for sanitizing or validating the content retrieved from the API before it is processed or displayed.
Audit Metadata