platform-apex-test-generate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use the official Salesforce CLI (sf) to execute tests and collect coverage metrics. This is standard behavior for development-focused skills and uses well-known developer tooling.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest local Apex source code and test execution results to perform automated fix loops. While this creates an ingestion surface for potentially untrusted data, it is a primary function of the skill and is intended for use within a local development environment.
  • Ingestion points: Reads contents of *Test.cls files and output from test coverage reports.
  • Boundary markers: Utilizes standard Apex class and method delimiters; no specific instructions provided to the agent to treat data as untrusted.
  • Capability inventory: The skill can perform file-write operations (creating .cls and .xml files) and execute shell commands (sf apex run test) based on its analysis.
  • Sanitization: Relies on the agent's internal logic for parsing Apex source code and Salesforce CLI output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 12:48 PM
Security Audit — agent-trust-hub — platform-apex-test-generate