platform-apex-anonymous-run
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
sf apex runcommand to execute logic against a connected Salesforce org. This capability allows for data manipulation (DML), external callouts, and event publication within the scope of the authenticated user. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface by ingesting and executing arbitrary Apex code provided by the user. 1. Ingestion points: Pasted code snippets in the conversation. 2. Boundary markers: The skill requires echoing the snippet back to the user and obtaining confirmation before execution. 3. Capability inventory: Shell command execution via
sfCLI and file writing. 4. Sanitization: It specifically avoids shell heredocs to prevent accidental shell expansion of code content, utilizing a dedicated file writing tool instead. - [DYNAMIC_EXECUTION]: The skill generates temporary
.apexfiles from user-supplied input and executes them at runtime. It also dynamically wraps user code inSavepointandDatabase.rollback()structures when verification-style execution is requested, modifying the executed source at runtime.
Audit Metadata