platform-apex-anonymous-run

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the sf apex run command to execute logic against a connected Salesforce org. This capability allows for data manipulation (DML), external callouts, and event publication within the scope of the authenticated user.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface by ingesting and executing arbitrary Apex code provided by the user. 1. Ingestion points: Pasted code snippets in the conversation. 2. Boundary markers: The skill requires echoing the snippet back to the user and obtaining confirmation before execution. 3. Capability inventory: Shell command execution via sf CLI and file writing. 4. Sanitization: It specifically avoids shell heredocs to prevent accidental shell expansion of code content, utilizing a dedicated file writing tool instead.
  • [DYNAMIC_EXECUTION]: The skill generates temporary .apex files from user-supplied input and executes them at runtime. It also dynamically wraps user code in Savepoint and Database.rollback() structures when verification-style execution is requested, modifying the executed source at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:21 PM
Security Audit — agent-trust-hub — platform-apex-anonymous-run